PT-2024-6165 · Microsoft · Office Onenote

Francesco Benvenuto

·

Published

2024-04-16

·

Updated

2025-08-25

·

CVE-2024-41159

CVSS v3.1
7.1
VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Microsoft OneNote version 16.83
Description A library injection vulnerability exists in Microsoft OneNote for macOS. This issue is related to incorrect cryptographic signature verification, allowing a specially crafted library to leverage OneNote's access privileges and bypass existing security restrictions. A malicious application could inject a library and start the program to trigger this vulnerability, then make use of the vulnerable application's permissions.
Recommendations For Microsoft OneNote version 16.83, consider disabling the application until a patch is available to prevent potential exploitation of the library injection vulnerability. Restrict access to the application to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Verification of Cryptographic Signature

Weakness Enumeration

Related Identifiers

BDU:2024-07085
CVE-2024-41159

Affected Products

Office Onenote