PT-2017-1638 · Microsoft · Excel Services On Sharepoint Server+2

Publicado

2017-03-14

·

Atualizado

2017-07-12

·

CVE-2017-0027

CVSS v3.1

4.7

Média

VetorAV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Excel versions 2007 SP3 through 2016 Office Compatibility Pack version SP3 Excel Services on SharePoint Server version 2013 SP1
Description The issue is related to the improper disclosure of memory contents by Microsoft Office, allowing remote attackers to obtain sensitive information from process memory via a crafted Office document. This could potentially be used to compromise the user's computer or data.
Recommendations For Microsoft Excel versions 2007 SP3 through 2016, update to a version that includes the fix for this issue. For Office Compatibility Pack version SP3, update to a version that includes the fix for this issue. For Excel Services on SharePoint Server version 2013 SP1, update to a version that includes the fix for this issue. As a temporary workaround, consider avoiding the use of crafted Office documents until a patch is available.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2017-00791
CVE-2017-0027

Produtos afetados

Excel Services On Sharepoint Server
Office Excel
Office Compatibility Pack