EXPOSURES › CVE-2014-4077
CVE-2014-4077
HIGH ⌖ ON CISA KEV · EXPLOITEDA default-installed Japanese IME on Windows allows sandbox bypass and privilege escalation via an unpatched vulnerability.
The Microsoft Japanese Input Method Editor (IME) shipped with Windows contains an unspecified vulnerability that lets attackers bypass sandbox protections and escalate privileges when IMJPDCT.EXE is installed. DIB organizations must ensure this component is patched or disabled, as it represents a high-risk, default-path attack surface that could enable lateral movement or data exfiltration. This failure is avoidable through timely patching and careful management of default Windows components.
Shame score — A default-installed, long-standing vulnerability in a core Windows component that enables privilege escalation and sandbox bypass, yet remained unpatched and actively exploited in the wild.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Input Method Editor (IME) Japanese is a keyboard with Japanese characters that can be enabled on Windows systems as it is included by default (with the default set as disabled). IME Japanese contains an unspecified vulnerability when IMJPDCT.EXE (IME for Japanese) is installed which allows attackers to bypass a sandbox and perform privilege escalation.
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |