CERT-In Vulnerability Note
CIVN-2013-0219
Microsoft Office Information Disclosure Vulnerability
Original Issue Date:December 11, 2013
Severity Rating: MEDIUM
Systems Affected
- Microsoft Office 2013 (32-bit editions)
- Microsoft Office 2013 (64-bit editions)
- Microsoft Office 2013 RT
Overview
An information disclosure vulnerability has been reported in Microsoft office which could allow a remote attacker to access to potentially sensitive information which may aid in further attacks.
Description
This vulnerability exists in Microsoft office due to improper handling of the crafted responses while opening an Office file. A remote attacker could exploit this vulnerability by persuading a user to open an Office file hosted on a malicious website using an affected version of Microsoft Office.
Successful exploitation could allow the remote attacker to access sensitive information such as access tokens used to authenticate the current user on a targeted SharePoint or other Microsoft Office server site.
Solution
Apply appropriate patches as mentioned in the Microsoft Security Bulletin
MS13-104
Vendor Information
Microsoft
https://technet.microsoft.com/en-us/security/bulletin/ms13-104
References
Cisco
http://tools.cisco.com/security/center/viewAlert.x?alertId=31989
Securitytracker
http://securitytracker.com/id/1029464
CVE Name
CVE-2013-5054
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|