PT-2009-1538 · Microsoft · Word 2007

Publicado

2009-02-05

·

Atualizado

2018-10-11

·

CVE-2008-6063

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Word 2007
Description The issue allows remote attackers to obtain sensitive information, such as the sender's account name and a Temporary Internet Files subdirectory name, when the "Save as PDF" add-on is enabled and an "Email as PDF" operation is performed. This occurs because Microsoft Word 2007 places an absolute pathname in the Subject field.
Recommendations For Microsoft Word 2007, consider disabling the "Save as PDF" add-on to prevent sensitive information disclosure until a fix is available. Restrict the use of the "Email as PDF" operation to minimize the risk of exploitation.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-6063

Produtos afetados

Word 2007