PT-2017-1638 · Microsoft · Excel Services On Sharepoint Server+2

Published

2017-03-14

·

Updated

2017-07-12

·

CVE-2017-0027

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Excel versions 2007 SP3 through 2016 Office Compatibility Pack version SP3 Excel Services on SharePoint Server version 2013 SP1
Description The issue is related to the improper disclosure of memory contents by Microsoft Office, allowing remote attackers to obtain sensitive information from process memory via a crafted Office document. This could potentially be used to compromise the user's computer or data.
Recommendations For Microsoft Excel versions 2007 SP3 through 2016, update to a version that includes the fix for this issue. For Office Compatibility Pack version SP3, update to a version that includes the fix for this issue. For Excel Services on SharePoint Server version 2013 SP1, update to a version that includes the fix for this issue. As a temporary workaround, consider avoiding the use of crafted Office documents until a patch is available.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-00791
CVE-2017-0027

Affected Products

Excel Services On Sharepoint Server
Office Excel
Office Compatibility Pack