Skip to main content

Microsoft Office Token Hijacking Vulnerability

Last Update Date: 13 Dec 2013 Release Date: 11 Dec 2013 3682 Views

RISK: Medium Risk

TYPE: Clients - Productivity Products

TYPE: Productivity Products

An information disclosure vulnerability exists when affected Microsoft Office software does not properly handle a specially crafted response while attempting to open an Office file hosted on the malicious website. An attacker who successfully exploited this vulnerability could ascertain access tokens used to authenticate the current user on a targeted SharePoint or other Microsoft Office server site.


Impact

  • Information Disclosure

System / Technologies affected

  • Microsoft Office 2013 and Microsoft Office 2013 RT

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link