Microsoft Office Token Hijacking Vulnerability
RISK: Medium Risk
TYPE: Clients - Productivity Products
An information disclosure vulnerability exists when affected Microsoft Office software does not properly handle a specially crafted response while attempting to open an Office file hosted on the malicious website. An attacker who successfully exploited this vulnerability could ascertain access tokens used to authenticate the current user on a targeted SharePoint or other Microsoft Office server site.
Impact
- Information Disclosure
System / Technologies affected
- Microsoft Office 2013 and Microsoft Office 2013 RT
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Download location for patches:
http://technet.microsoft.com/en-us/security/bulletin/MS13-104
Vulnerability Identifier
Source
Related Link
Share with