#VU24266 Spoofing attack in Office Online Server - CVE-2020-0647
Published: January 14, 2020
Office Online Server
Microsoft
Description
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to the Office Online does not validate origin in cross-origin communications correctly. A remote attacker can send a specially crafted request to an affected site, perform cross-origin attacks on affected systems and gain access to sensitive information.