Information disclosure in Microsoft Office - CVE-2017-11939

 

Information disclosure in Microsoft Office - CVE-2017-11939

Published: December 12, 2017 / Updated: December 12, 2017


Vulnerability identifier: #VU9645
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2017-11939
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Microsoft
Affected software:
Microsoft Office

Detailed vulnerability description

The vulnerability allows a remote attacker to obtain potentially sensitive information.

An information disclosure vulnerability exists when Microsoft Outlook fails to enforce copy/paste permissions on DRM-protected emails. An attacker who successfully exploited the vulnerability could potentially extract plaintext content from DRM-protected draft emails.

The vulnerability should be exploited exploited along with another vulnerability to access the victim's Drafts folder, either locally on the victim's system or remotely via MAPI.


How to mitigate CVE-2017-11939

Install updates from vendor's website.

Sources