CVE-2014-4077 is an Elevation of Privilege vulnerability affecting multiple Microsoft Windows versions and Office 2007 SP3 when the Japanese IME (IMJPDCT.EXE) is installed. It allows remote attackers to bypass a sandbox protection mechanism through a crafted PDF document, requiring user interaction. With a CVSS v3.1 score of 7.8 (HIGH), successful exploitation can lead to high impacts on confidentiality, integrity, and availability. This vulnerability was actively exploited in the wild in 2014 and is listed on the CISA KEV catalog, indicating ongoing risk despite no public exploit modules.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
sp3CPE matchmatch criteria | cpe:2.3:a:microsoft:office_2007_ime:sp3:*:*:ja:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2003:-:sp2:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:* | ||
r2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:itanium:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.