René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

90 lines
2.8 KiB
JSON

{
"id": "CVE-2010-1254",
"sourceIdentifier": "secure@microsoft.com",
"published": "2010-06-08T20:30:02.333",
"lastModified": "2018-10-12T21:57:28.497",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "The installation for Microsoft Open XML File Format Converter for Mac sets insecure ACLs for the /Applications folder, which allows local users to execute arbitrary code by replacing the executable with a Trojan Horse, aka \"Mac Office Open XML Permissions Vulnerability.\""
},
{
"lang": "es",
"value": "La instalaci\u00f3n de Microsoft Open XML File Format Converter para Mac asigna ACLs inseguros a la carpeta /Applications, lo que permite a usuarios locales ejecutar c\u00f3digo de su elecci\u00f3n mediante la sustituci\u00f3n del ejecutable con un caballo de Troya. Esta vulnerabilidad tambi\u00e9n es conocida como \"Vulnerabilidad de permisos en Open XML para Mac Office\""
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:L/AC:M/Au:N/C:C/I:C/A:C",
"accessVector": "LOCAL",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "COMPLETE",
"integrityImpact": "COMPLETE",
"availabilityImpact": "COMPLETE",
"baseScore": 6.9
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 3.4,
"impactScore": 10.0,
"acInsufInfo": false,
"obtainAllPrivilege": true,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:open_xml_file_format_converter:*:*:mac:*:*:*:*:*",
"matchCriteriaId": "3807A4E4-EB58-47B6-AD98-6ED464DEBA4E"
}
]
}
]
}
],
"references": [
{
"url": "http://www.securityfocus.com/bid/40533",
"source": "secure@microsoft.com"
},
{
"url": "http://www.us-cert.gov/cas/techalerts/TA10-159B.html",
"source": "secure@microsoft.com",
"tags": [
"US Government Resource"
]
},
{
"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-038",
"source": "secure@microsoft.com"
}
]
}