PT-2022-3303 · Microsoft · Office+3
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Office (affected versions not specified)
Microsoft SharePoint Server (affected versions not specified)
Microsoft SharePoint Enterprise Server (affected versions not specified)
Microsoft Office Web Apps Server (affected versions not specified)
Microsoft Office Online Server (affected versions not specified)
Description
The issue is related to insufficient protection of service data, which can be exploited by opening a specially crafted malicious file, allowing an attacker to gain unauthorized access to protected information. This is an information disclosure issue that affects the system.
Recommendations
For Microsoft Office, update to a version that includes the fix for this issue.
For Microsoft SharePoint Server, consider restricting access to sensitive data until a patch is available.
For Microsoft SharePoint Enterprise Server, Microsoft Office Web Apps Server, and Microsoft Office Online Server, restrict access to potentially vulnerable components to minimize the risk of exploitation.
As a temporary workaround, consider avoiding the use of potentially vulnerable features in these products until a patch is available.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Office
Office Online Server
Office Web Apps Server
Sharepoint Server