CVE-2017-11934 Information
Feb 14, 2021
cve
Description
Microsoft Office 2013 RT SP1 Microsoft Office 2013 SP1 and Microsoft Office 2016 allow an information disclosure vulnerability due to the way certain functions handle objects in memory aka \Microsoft Office Information Disclosure Vulnerability.
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Reference
http://www.securityfocus.com/bid/102064 http://www.securitytracker.com/id/1039998 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11934
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
5.5
Share on: