CVE-2007-6329: Medium severity Microsoft Office vulnerability
Microsoft Office 2007 12.0.6015.5000 and MSO 12.0.6017.5000 do not sign the metadata of Office Open XML (OOXML) documents, which makes it easier for remote attackers to modify Dublin Core metadata fields, as demonstrated by the (1) LastModifiedBy and (2) creator fields in docProps/core.xml in the OOXML ZIP container.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-6329?
CVE-2007-6329 has been classified as a moderate severity vulnerability.
How do I fix CVE-2007-6329?
To fix CVE-2007-6329, update Microsoft Office 2007 to the latest version provided by Microsoft.
What are the potential impacts of CVE-2007-6329?
The impact of CVE-2007-6329 includes the possibility for attackers to manipulate metadata within Office Open XML documents.
Which versions of Microsoft Office are affected by CVE-2007-6329?
CVE-2007-6329 affects Microsoft Office 2007 versions 12.0.6015.5000 and 12.0.6017.5000.
What type of metadata can be modified due to CVE-2007-6329?
CVE-2007-6329 allows modification of Dublin Core metadata fields like LastModifiedBy and creator in OOXML documents.