First published: Wed Apr 12 2017(Updated: )
Microsoft OneNote 2007 SP3 and Microsoft OneNote 2010 SP2 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office DLL Loading Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft OneNote 2010 | =2007-sp3 | |
Microsoft OneNote 2010 | =2010-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-0197 is considered to have a critical severity rating due to its potential for remote code execution.
To fix CVE-2017-0197, users should update Microsoft OneNote to the latest Service Pack for their version.
CVE-2017-0197 affects Microsoft OneNote 2007 SP3 and Microsoft OneNote 2010 SP2.
CVE-2017-0197 can allow remote attackers to execute arbitrary code via a specially crafted document.
Yes, exploitation of CVE-2017-0197 typically requires the user to open a crafted document.