CVE-2013-0095: Infoleak
Outlook in Microsoft Office for Mac 2008 before 12.3.6 and Office for Mac 2011 before 14.3.2 allows remote attackers to trigger access to a remote URL and consequently confirm the rendering of an HTML e-mail message by including unspecified HTML5 elements and leveraging the installation of a WebKit browser on the victim's machine, aka "Unintended Content Loading Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0095?
CVE-2013-0095 is classified as a moderate severity vulnerability.
How do I fix CVE-2013-0095?
To fix CVE-2013-0095, you should update Microsoft Office for Mac to version 12.3.6 or 14.3.2 or later.
What versions of Microsoft Office for Mac are affected by CVE-2013-0095?
CVE-2013-0095 affects Microsoft Office for Mac 2008 versions prior to 12.3.6 and Office for Mac 2011 versions prior to 14.3.2.
What type of attack does CVE-2013-0095 allow?
CVE-2013-0095 allows remote attackers to confirm the rendering of HTML email messages by exploiting HTML5 elements.
What is the impact of exploiting CVE-2013-0095?
Exploiting CVE-2013-0095 can potentially allow attackers to access a remote URL without user consent.