Microsoft APP-V Security Feature Bypass Vulnerability
🔗 CVE IDs covered (1)
📋 Description
An information disclosure vulnerability exists in the way that the Click-to-Run (C2R) components handle objects in memory, which could lead to an Address Space Layout Randomization (ASLR) bypass. An attacker who successfully exploited the information disclosure vulnerability could use the obtained information to bypass the ASLR security mechanism in Windows, which helps protect users from a broad class of vulnerabilities. The ASLR bypass by itself does not allow arbitrary code execution; however, an attacker could use the ASLR bypass in conjunction with another vulnerability, such as a remote code execution vulnerability, that could leverage the ASLR bypass to run arbitrary code. To exploit the ASLR bypass, an attacker would have to log on to an affected system and run a specially crafted application. Workstations are primarily vulnerable to the potential ASLR bypass. The security update addresses the ASLR bypass by correcting how C2R components handle memory addresses.
🎯 Affected products2
- Microsoft Office 2013 Service Pack 1 (32-bit editions)
- Microsoft Office 2013 Service Pack 1 (64-bit editions)
✅ Remediation
KBClick to Run (Security Update)