CVE-2014-4077
unknown
KEV
CVSS v3
—
CVSS v2
—
VIR risk
1.5
Description
Microsoft Input Method Editor (IME) Japanese is a keyboard with Japanese characters that can be enabled on Windows systems as it is included by default (with the default set as disabled). IME Japanese contains an unspecified vulnerability when IMJPDCT.EXE (IME for Japanese) is installed which allows attackers to bypass a sandbox and perform privilege escalation.
CISA KEV
- Vendor
- Microsoft
- Product
- Input Method Editor (IME) Japanese
- Due date
- 2022-06-15
Predictions
Exploit likelihood
99%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cisa-kev — https://nvd.nist.gov/vuln/detail/CVE-2014-4077
Exploits
References
Verify integrity in audit chain (admin only). AS-IS.