CVE-2014-4077
KEVmassSandbox Escape Privilege Escalation in Microsoft Japanese IME (Windows)
CISA: Microsoft IME Japanese Privilege Escalation Vulnerability
CVE-2014-4077 is an elevation-of-privilege flaw in the Japanese Input Method Editor (IME) that ships with Windows, involving the IME component IMJPDCT.EXE. The flaw is triggered on systems where the Japanese IME component is present (it is included by default with Windows, though disabled by default), and it allows an attacker who has already gained code execution in a sandboxed or low-privileged context to bypass that sandbox. Successful exploitation yields elevated privileges on the host, typically enabling full system control, and such local privilege escalation flaws are commonly chained with other vulnerabilities in malware and ransomware campaigns. Any Windows system carrying the Japanese IME is affected, with Japanese-locale environments being the most directly relevant deployments. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-05-25, confirming exploitation in the wild; EPSS estimates a ~55% probability of exploitation within 30 days (99th percentile), while no public proof-of-concept is known.
What to do: Apply the Microsoft security updates released in the November 2014 Patch Tuesday cycle (MS14-071) that fix the Japanese IME vulnerability, per the CISA KEV required action to apply updates per vendor instructions. Prioritize user endpoints and shared systems where untrusted code runs, since a local sandbox escape here can lead to full host compromise and onward lateral movement in ransomware chains, and verify IMJPDCT.EXE/Japanese IME remediation to satisfy KEV compliance. As an interim mitigation, restrict execution of untrusted code on hosts pending patching, because exploitation requires an attacker to already have code running locally.
| Microsoft Input Method Editor (IME) Japanese (IMJPDCT.EXE) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft Input Method Editor (IME) Japanese is a keyboard with Japanese characters that can be enabled on Windows systems as it is included by default (with the default set as disabled). IME Japanese contains an unspecified vulnerability when IMJPDCT.EXE (IME for Japanese) is installed which allows attackers to bypass a sandbox and perform privilege escalation.
- Affected
- Microsoft Input Method Editor (IME) Japanese
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- Microsoft
- Products
- Input Method Editor (IME) Japanese
- Weakness
- CWE-264