Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2cgq-hh5m-vc66

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An elevation of privilege vulnerability exists in Microsoft Office OLicenseHeartbeat task, where an attacker who successfully exploited this vulnerability could run this task as SYSTEM.To exploit the vulnerability, an authenticated attacker would need to place a specially crafted file in a specific location, thereby allowing arbitrary file corruption.The security update addresses the vulnerability by correcting how the process validates the log file., aka 'Microsoft Office Tampering Vulnerability'.

An elevation of privilege vulnerability exists in Microsoft Office OLicenseHeartbeat task, where an attacker who successfully exploited this vulnerability could run this task as SYSTEM.To exploit the vulnerability, an authenticated attacker would need to place a specially crafted file in a specific location, thereby allowing arbitrary file corruption.The security update addresses the vulnerability by correcting how the process validates the log file., aka 'Microsoft Office Tampering Vulnerability'.

EPSS

Процентиль: 47%
0.00243
Низкий

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 7.8
nvd
почти 6 лет назад

An elevation of privilege vulnerability exists in Microsoft Office OLicenseHeartbeat task, where an attacker who successfully exploited this vulnerability could run this task as SYSTEM.To exploit the vulnerability, an authenticated attacker would need to place a specially crafted file in a specific location, thereby allowing arbitrary file corruption.The security update addresses the vulnerability by correcting how the process validates the log file., aka 'Microsoft Office Tampering Vulnerability'.

msrc
почти 6 лет назад

Microsoft Office Elevation of Privilege Vulnerability

CVSS3: 7.8
fstec
почти 6 лет назад

Уязвимость задачи OLicenseHeartbeat пакета программ Microsoft Office, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 47%
0.00243
Низкий

Дефекты

CWE-269