CVE-2016-3315: Infoleak
Published Aug 9, 2016
·Updated
Microsoft OneNote 2007 SP3, 2010 SP2, 2013 SP1, 2013 RT SP1, 2016, and 2016 for Mac allow remote attackers to obtain sensitive information via a crafted OneNote file, aka "Microsoft OneNote Information Disclosure Vulnerability."
Affected Software
6 affected components
Microsoft OneNote=2007-sp3
Microsoft OneNote=2010-sp2
Microsoft OneNote=2013-sp1
Microsoft OneNote=2013-sp1
Microsoft OneNote=2016
Microsoft OneNote for Mac=2016
Event History
Aug 9, 2016
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-3315?
CVE-2016-3315 has a severity rating of important as it can lead to information disclosure.
2
How do I fix CVE-2016-3315?
To fix CVE-2016-3315, update to the latest version of Microsoft OneNote that addresses this vulnerability.
3
What versions of Microsoft OneNote are affected by CVE-2016-3315?
CVE-2016-3315 affects Microsoft OneNote 2007 SP3, 2010 SP2, 2013 SP1, 2016, and 2016 for Mac.
4
What type of vulnerability is CVE-2016-3315?
CVE-2016-3315 is categorized as an information disclosure vulnerability.
5
Can CVE-2016-3315 be exploited remotely?
Yes, CVE-2016-3315 can be exploited remotely through a crafted OneNote file.