First published: Wed Apr 12 2017(Updated: )
Microsoft Excel 2007 SP3, Microsoft Excel 2010 SP2, and Office Compatibility Pack SP2 allow remote attackers to obtain sensitive information from process memory via a crafted Office document, aka "Microsoft Office Information Disclosure Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office Excel | =2007-sp3 | |
Microsoft Office Excel | =2010-sp2 | |
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint | =sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-0194 has been classified as a critical vulnerability that allows information disclosure in Microsoft Excel.
To fix CVE-2017-0194, users should apply the latest security updates provided by Microsoft for the affected versions of Excel and the Office Compatibility Pack.
CVE-2017-0194 affects Microsoft Excel 2007 SP3, Microsoft Excel 2010 SP2, and the Office Compatibility Pack SP2.
CVE-2017-0194 is classified as an information disclosure vulnerability that allows remote attackers to access sensitive information from process memory.
Yes, CVE-2017-0194 can be exploited remotely via a crafted Office document.