PT-2022-17794 · Microsoft · Outlook+1

Craig Haft

·

Published

2022-03-04

·

Updated

2022-12-07

·

CVE-2022-26336

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions poi-scratchpad versions 5.2.0 and prior versions
Description A shortcoming in the HMEF package of poi-scratchpad allows an attacker to cause an Out of Memory exception. This package is used to read TNEF files, which are associated with Microsoft Outlook and Microsoft Exchange Server. If an application uses poi-scratchpad to parse TNEF files and allows untrusted users to supply them, a carefully crafted file can cause an Out of Memory exception.
Recommendations To resolve the issue, upgrade to poi-scratchpad version 5.2.1. As a temporary workaround, consider restricting the use of the HMEF package to minimize the risk of exploitation. Avoid allowing untrusted users to supply TNEF files to applications that use poi-scratchpad until the issue is resolved.

Fix

Allocation of Resources Without Limits

RCE

Weakness Enumeration

Related Identifiers

CVE-2022-26336
GHSA-MQVP-7RRG-9JXC

Affected Products

Exchange Server
Outlook