First published: Wed Dec 11 2013(Updated: )
Microsoft Office 2013 and 2013 RT allows remote attackers to discover authentication tokens via a crafted response to a file-open request for an Office file on a web site, as exploited in the wild in 2013, aka "Token Hijacking Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office | =2013 | |
Microsoft Office | =2013 | |
Microsoft Office 2013 RT |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5054 is classified as a critical vulnerability due to its potential to allow attackers to hijack authentication tokens.
To resolve CVE-2013-5054, users should apply the latest security updates provided by Microsoft for Office 2013 and Office 2013 RT.
CVE-2013-5054 can be exploited through crafted responses to file-open requests, enabling token hijacking.
CVE-2013-5054 affects Microsoft Office 2013 and Microsoft Office 2013 RT in both x64 and x86 architectures.
While CVE-2013-5054 was reported in 2013, its relevance may persist in environments using outdated versions of Microsoft Office.