Information Disclosure in Microsoft OneNote in Microsoft products - CVE-2016-3315
Published: August 10, 2016 / Updated: January 9, 2017
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to out-of-bound read when handling objects in memory. A remote attacker can create a specially crafted OneNote file and convince a victim to open it.
Successful exploitation of this vulnerability my allow an attacker to obtain potentially sensitive information but requires knowledge of the specific location of OneNote objects in memory.
Affected software
Microsoft OneNote
Microsoft Office for macOS