PT-2021-2724 · Microsoft · Office Online Server+4

Willj

+1

·

Published

2021-04-13

·

Updated

2023-12-29

·

CVE-2021-28456

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Office versions (affected versions not specified) Microsoft Office Web Apps Server versions (affected versions not specified) Microsoft Excel versions (affected versions not specified) Microsoft 365 Apps for Enterprise versions (affected versions not specified) Microsoft Office Online Server versions (affected versions not specified)
Description The issue is related to insufficient protection of sensitive data in Microsoft products. It may allow an attacker to gain unauthorized access to protected information. An information disclosure vulnerability in Microsoft Excel can be exploited to affect the system.
Recommendations For Microsoft Office, update to a version that includes the fix for this issue. For Microsoft Office Web Apps Server, apply the necessary configuration changes to mitigate the risk. For Microsoft Excel, consider restricting access to sensitive data until a patch is available. For Microsoft 365 Apps for Enterprise, update to a version that includes the fix for this issue. For Microsoft Office Online Server, apply the necessary security updates to resolve the issue.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-02258
CVE-2021-28456

Affected Products

365 Apps For Enterprise
Office Excel
Office
Office Online Server
Office Web Apps Server