An elevation of privilege vulnerability exists in the way that Microsoft Office Click-to-Run (C2R) components handle objects in memory, aka ‘Microsoft Office Click-to-Run Elevation of Privilege Vulnerability’.