CVE-2011-2010 describes an elevation of privilege vulnerability in the Microsoft Office Input Method Editor (IME) for Simplified Chinese, specifically affecting Microsoft Pinyin IME 2010, Office Pinyin SimpleFast Style 2010, and Office Pinyin New Experience Style 2010. This flaw allows local users to gain elevated privileges by manipulating configuration options via the Microsoft Pinyin IME toolbar. The vulnerability carries a CVSS score of 7.2, indicating high severity with a local attack vector and low attack complexity, potentially leading to complete compromise of confidentiality, integrity, and availability. Its EPSS score is low, suggesting a low probability of exploitation. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion is minimal, with only one mention found, and there is no media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:pinyin_ime:2010:*:x64:*:*:*:*:* | ||
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:pinyin_ime:2010:*:x86:*:*:*:*:* | ||
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:pinyin_new_experience_style:2010:*:x64:*:*:*:*:* | ||
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:pinyin_new_experience_style:2010:*:x86:*:*:*:*:* | ||
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:pinyin_simple_fast_style:2010:*:x64:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.