CVE-2016-0141High
Microsoft Office Information Disclosure Vulnerability
🔗 CVE IDs covered (1)
📋 Description
An information disclosure vulnerability exists when Microsoft Outlook fails to enforce copy/paste permissions on DRM-protected emails. An attacker who successfully exploited the vulnerability could potentially extract plaintext content from DRM-protected draft emails. The attacker would have to use another vulnerability to gain access to the victim's Drafts folder, either locally on the victim's system or remotely via MAPI. The security update addresses the vulnerability by correcting how Microsoft Outlook enforces DRM copy/paste permissions.
🎯 Affected products7
- Microsoft Office 2007 Service Pack 3
- Microsoft Office 2010 Service Pack 2 (32-bit editions)
- Microsoft Office 2010 Service Pack 2 (64-bit editions)
- Microsoft Office 2013 Service Pack 1 (32-bit editions)
- Microsoft Office 2013 Service Pack 1 (64-bit editions)
- Microsoft Office 2016 (32-bit edition)
- Microsoft Office 2016 (64-bit edition)
✅ Remediation
KB3118268 (Security Update) KB3118309 (Security Update) KB3118300 (Security Update) KB3118292 (Security Update)
🔗 References (8)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2016-0141
- patchhttps://www.microsoft.com/download/details.aspx?familyid=c582868a-0631-4bfd-ae12-adc54778fd25
- patchhttps://www.microsoft.com/download/details.aspx?familyid=8e15cbb1-5400-463e-b38b-f0fbfc65b390
- patchhttps://www.microsoft.com/download/details.aspx?familyid=ca5536b1-a706-4694-b6bc-98ce162a1eb6
- patchhttps://www.microsoft.com/download/details.aspx?familyid=3abc23a3-ec3a-49c4-9e49-991c46c3c137
- patchhttps://www.microsoft.com/download/details.aspx?familyid=32311a8f-aa2f-4cf2-b63c-f3911cba8eed
- patchhttps://www.microsoft.com/download/details.aspx?familyid=b50e8984-03e4-4803-8d1f-f7f7ddbedcee
- patchhttps://www.microsoft.com/download/details.aspx?familyid=66fb8f08-3170-4e72-b65c-4fdab2a214c5