#VU9645 Information disclosure in Microsoft Office - CVE-2017-11939

 

#VU9645 Information disclosure in Microsoft Office - CVE-2017-11939

Published: December 12, 2017 / Updated: December 12, 2017


Vulnerability identifier: #VU9645
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2017-11939
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Microsoft Office
Software vendor:
Microsoft

Description

The vulnerability allows a remote attacker to obtain potentially sensitive information.

An information disclosure vulnerability exists when Microsoft Outlook fails to enforce copy/paste permissions on DRM-protected emails. An attacker who successfully exploited the vulnerability could potentially extract plaintext content from DRM-protected draft emails.

The vulnerability should be exploited exploited along with another vulnerability to access the victim's Drafts folder, either locally on the victim's system or remotely via MAPI.


Remediation

Install updates from vendor's website.

External links