First published: Wed Mar 13 2013(Updated: )
Outlook in Microsoft Office for Mac 2008 before 12.3.6 and Office for Mac 2011 before 14.3.2 allows remote attackers to trigger access to a remote URL and consequently confirm the rendering of an HTML e-mail message by including unspecified HTML5 elements and leveraging the installation of a WebKit browser on the victim's machine, aka "Unintended Content Loading Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office | =2008 | |
Microsoft Office | =2011 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0095 is classified as a moderate severity vulnerability.
To fix CVE-2013-0095, you should update Microsoft Office for Mac to version 12.3.6 or 14.3.2 or later.
CVE-2013-0095 affects Microsoft Office for Mac 2008 versions prior to 12.3.6 and Office for Mac 2011 versions prior to 14.3.2.
CVE-2013-0095 allows remote attackers to confirm the rendering of HTML email messages by exploiting HTML5 elements.
Exploiting CVE-2013-0095 can potentially allow attackers to access a remote URL without user consent.