An elevation of privilege vulnerability exists in the way that Microsoft Office Click-to-Run (C2R) AppVLP handles certain files. An attacker who successfully exploited the vulnerability could elevate privileges. To exploit this vulnerability, an attacker would need to convince a user to open a specially crafted file. The security update addresses the vulnerability by correcting how Microsoft Office Click-to-Run (C2R) components handle these files.
Is the Preview Pane an attack vector for this vulnerability? No, the Preview Pane is not an attack vector.
marxixing of Kingsoft Cloud Security Team (@marxixing)