First published: Fri Mar 17 2017(Updated: )
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Services on SharePoint Server 2013 SP1 allow remote attackers to obtain sensitive information from process memory via a crafted Office document, aka "Microsoft Office Information Disclosure Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office Excel | =2007-sp3 | |
Microsoft Office Excel | =2010-sp2 | |
Microsoft Office Excel | =2013-sp1 | |
Microsoft Office Excel | =2016 | |
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint | =sp3 | |
Microsoft SharePoint Server 2010 | =2013-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-0027 has a severity rating that indicates a potential risk of information disclosure.
To resolve CVE-2017-0027, users should apply the latest security updates provided by Microsoft for their affected software.
CVE-2017-0027 affects Microsoft Excel 2007 SP3, 2010 SP2, 2013 RT SP1, and 2016, along with Office Compatibility Pack SP3 and SharePoint Server 2013 SP1.
CVE-2017-0027 is categorized as an information disclosure vulnerability which allows attackers to access sensitive information.
You can determine vulnerability to CVE-2017-0027 by checking the version of your Microsoft Excel or related software and whether security updates have been applied.