#VU295 Information Disclosure in Microsoft OneNote in Microsoft products - CVE-2016-3315

 

#VU295 Information Disclosure in Microsoft OneNote in Microsoft products - CVE-2016-3315

Published: August 10, 2016 / Updated: January 9, 2017


Vulnerability identifier: #VU295
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2016-3315
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Microsoft Office
Microsoft OneNote
Microsoft Office for macOS
Software vendor:
Microsoft

Description

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to out-of-bound read when handling objects in memory. A remote attacker can create a specially crafted OneNote file and convince a victim to open it.

Successful exploitation of this vulnerability my allow an attacker to obtain potentially sensitive information but requires knowledge of the specific location of OneNote objects in memory.


Remediation


External links