Cross-site scripting in Microsoft Outlook and Microsoft Office - CVE-2018-0850
Published: February 13, 2018 / Updated: February 13, 2018
Microsoft Outlook
Microsoft Office
Detailed vulnerability description
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of emails. A remote attacker can trick the victim to connect to malicious SMB share and execute arbitrary HTML and script code within Microsoft Outlook context.