First published: Wed Nov 11 2015(Updated: )
Cross-site scripting (XSS) vulnerability in Microsoft Excel for Mac 2011 and Excel 2016 for Mac allows remote attackers to inject arbitrary web script or HTML via a crafted e-mail message that is mishandled by Outlook for Mac, aka "Microsoft Outlook for Mac Spoofing Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Excel | =2011 | |
Microsoft Excel | =2016 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6123 is considered a critical cross-site scripting vulnerability that can allow attackers to inject arbitrary web scripts or HTML.
To fix CVE-2015-6123, users should update Microsoft Excel for Mac to the latest version that addresses this vulnerability.
CVE-2015-6123 affects Microsoft Excel for Mac 2011 and Excel 2016 for Mac.
CVE-2015-6123 enables attackers to exploit cross-site scripting to inject malicious scripts via crafted email messages.
Remote attackers can exploit CVE-2015-6123 by sending specially crafted email messages to users of the affected Excel applications.