Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2017-11939

Опубликовано: 12 дек. 2017
Источник: msrc
EPSS Низкий

Описание

Microsoft Office Information Disclosure Vulnerability

An information disclosure vulnerability exists when Microsoft Outlook fails to enforce copy/paste permissions on DRM-protected emails. An attacker who successfully exploited the vulnerability could potentially extract plaintext content from DRM-protected draft emails.

The attacker would have to use another vulnerability to gain access to the victim's Drafts folder, either locally on the victim's system or remotely via MAPI.

The security update addresses the vulnerability by correcting how Microsoft Outlook enforces DRM copy/paste permissions.

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

N/A

DOS

N/A

EPSS

Процентиль: 83%
0.02117
Низкий

Связанные уязвимости

CVSS3: 6.5
nvd
больше 7 лет назад

Microsoft Office 2016 Click-to-Run (C2R) allows an information disclosure vulnerability due to the way Microsoft Office enforces DRM copy/paste permissions, aka "Microsoft Office Information Disclosure Vulnerability".

CVSS3: 6.5
github
около 3 лет назад

Microsoft Office 2016 Click-to-Run (C2R) allows an information disclosure vulnerability due to the way Microsoft Office enforces DRM copy/paste permissions, aka "Microsoft Office Information Disclosure Vulnerability".

EPSS

Процентиль: 83%
0.02117
Низкий