First published: Tue Dec 12 2017(Updated: )
Microsoft Office 2013 RT SP1, Microsoft Office 2013 SP1, and Microsoft Office 2016 allow an information disclosure vulnerability due to the way certain functions handle objects in memory, aka "Microsoft Office Information Disclosure Vulnerability".
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office | =2013-sp1 | |
Microsoft Office | =2016 | |
Microsoft Office for Mac OS X | =2016 | |
Microsoft Office | =2016-c2r |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-11934 has a severity rating that indicates it allows for potential information disclosure.
To fix CVE-2017-11934, it is recommended to apply the latest security updates from Microsoft for affected versions of Office.
CVE-2017-11934 affects Microsoft Office 2013 SP1 and Microsoft Office 2016.
CVE-2017-11934 is classified as an information disclosure vulnerability due to improper handling of objects in memory.
CVE-2017-11934 requires local access to the system, meaning it cannot be exploited remotely without prior access.