MEDIUM · 6.9

CVE-2010-1254

The installation for Microsoft Open XML File Format Converter for Mac sets insecure ACLs for the /Applications folder, which allows local users to execute arbitrary code by replacing the executable wi...

Vulnerability Description

The installation for Microsoft Open XML File Format Converter for Mac sets insecure ACLs for the /Applications folder, which allows local users to execute arbitrary code by replacing the executable with a Trojan Horse, aka "Mac Office Open XML Permissions Vulnerability."

CVSS Score

6.9

MEDIUM

AV:L/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
MicrosoftOpen Xml File Format ConverterAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2010-1254?

CVE-2010-1254 is a vulnerability with a CVSS score of 6.9 (MEDIUM). The installation for Microsoft Open XML File Format Converter for Mac sets insecure ACLs for the /Applications folder, which allows local users to execute arbitrary code by replacing the executable wi...

How severe is CVE-2010-1254?

CVE-2010-1254 has been rated MEDIUM with a CVSS base score of 6.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2010-1254?

Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Open Xml File Format Converter.