Information Disclosure in Microsoft OneNote in Microsoft products - CVE-2016-3315

 

Information Disclosure in Microsoft OneNote in Microsoft products - CVE-2016-3315

Published: August 10, 2016 / Updated: January 9, 2017


Vulnerability identifier: #VU295
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2016-3315
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Microsoft
Affected software:
Microsoft Office
Microsoft OneNote
Microsoft Office for macOS

Detailed vulnerability description

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to out-of-bound read when handling objects in memory. A remote attacker can create a specially crafted OneNote file and convince a victim to open it.

Successful exploitation of this vulnerability my allow an attacker to obtain potentially sensitive information but requires knowledge of the specific location of OneNote objects in memory.


How to mitigate CVE-2016-3315


Sources