PT-2022-3303 · Microsoft · Office+3

·

CVE-2022-30171

·

Published

2022-06-14

·

Updated

2025-01-02

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Office (affected versions not specified) Microsoft SharePoint Server (affected versions not specified) Microsoft SharePoint Enterprise Server (affected versions not specified) Microsoft Office Web Apps Server (affected versions not specified) Microsoft Office Online Server (affected versions not specified)
Description The issue is related to insufficient protection of service data, which can be exploited by opening a specially crafted malicious file, allowing an attacker to gain unauthorized access to protected information. This is an information disclosure issue that affects the system.
Recommendations For Microsoft Office, update to a version that includes the fix for this issue. For Microsoft SharePoint Server, consider restricting access to sensitive data until a patch is available. For Microsoft SharePoint Enterprise Server, Microsoft Office Web Apps Server, and Microsoft Office Online Server, restrict access to potentially vulnerable components to minimize the risk of exploitation. As a temporary workaround, consider avoiding the use of potentially vulnerable features in these products until a patch is available.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-04041
CVE-2022-30171

Affected Products

Office
Office Online Server
Office Web Apps Server
Sharepoint Server