Vulnerability record · CVE-2014-4077 · published 11 November 2014
CVE-2014-4077: Microsoft IME Japanese sandbox bypass via crafted PDF
Microsoft · Office 2007 Ime
When the Japanese IME component (IMJPDCT.EXE) is installed on affected Windows and Office 2007 systems, a crafted PDF can bypass a sandbox protection mechanism. This is an elevation-of-privilege flaw that Microsoft confirmed was exploited in the wild in 2014, and it remains in CISA's KEV catalog.
Description
Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Office 2007 SP3, when IMJPDCT.EXE (aka IME for Japanese) is installed, allow remote attackers to bypass a sandbox protection mechanism via a crafted PDF document, aka "Microsoft IME (Japanese) Elevation of Privilege Vulnerability," as exploited in the wild in 2014.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is a confirmed in-the-wild sandbox escape listed in KEV with very high EPSS, but exploitation requires user interaction and the affected platforms are largely legacy.
What it is
When the Japanese IME component (IMJPDCT.EXE) is installed on affected Windows and Office 2007 systems, a crafted PDF can bypass a sandbox protection mechanism. This is an elevation-of-privilege flaw that Microsoft confirmed was exploited in the wild in 2014, and it remains in CISA's KEV catalog.
Impact
An attacker who gets code running in a sandboxed context can escape that sandbox and gain the privileges of the IME process, leading to full compromise of confidentiality, integrity and availability on the host.
Attack surface
Reached locally by opening a malicious PDF on a system with the Japanese IME installed; the CVSS vector requires user interaction (UI:R) but no privileges (PR:N), so a victim must open the crafted document.
Exploitation
Listed in CISA KEV since 2022-05-25 with a required action to apply vendor updates, and EPSS shows a 30-day probability of 0.549 (98.9th percentile); the description states it was exploited in the wild in 2014.
What to do
- Apply the Microsoft fix from MS14-078 (KB3002885) to all affected Windows and Office 2007 systems.
- Remove or disable the Japanese IME (IMJPDCT.EXE) on hosts that do not require it.
- Block or strip untrusted PDF attachments at mail and web gateways where feasible.
- Prioritize patching of any remaining Windows Server 2003, Vista, Server 2008, Windows 7 and Office 2007 SP3 hosts, which are all end-of-life.
Detection
- Hunt for IMJPDCT.EXE spawning unexpected child processes or loading unusual modules.
- Monitor for PDF readers launching IME-related executables or other anomalous process chains.
- Alert on suspicious process creation events originating from document viewers on hosts with the Japanese IME installed.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2014-4077 to the Known Exploited Vulnerabilities catalog on 25 May 2022 as "Microsoft IME Japanese Privilege Escalation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 June 2022.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://blogs.technet.com/b/srd/archive/2014/11/11/assessing-risk-for-the-november-2014-security-updates.aspx | Not ApplicableVendor Advisory |
| http://www.securitytracker.com/id/1031196 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1031197 | Broken LinkThird Party AdvisoryVDB Entry |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-078 | PatchVendor Advisory |
| http://blogs.technet.com/b/srd/archive/2014/11/11/assessing-risk-for-the-november-2014-security-updates.aspx | Not ApplicableVendor Advisory |
| http://www.securitytracker.com/id/1031196 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1031197 | Broken LinkThird Party AdvisoryVDB Entry |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-078 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-4077 | US Government Resource |
Track CVE-2014-4077 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-4077), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.