Spoofing attack in Office Online Server - CVE-2019-1447
Published: November 12, 2019
Office Online Server
Detailed vulnerability description
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to Office Online Server improperly validates origin in cross-origin communications handlers. A remote attacker can send a specially crafted request to the affected website and perform a spoofing attack against an authenticated user.
Successful exploitation of the vulnerability may allow an attacker gain access to victim's account.