Microsoft Office 2016 Click-to-Run (C2R) allows an information disclosure vulnerability due to the way Microsoft Office enforces DRM copy/paste permissions, aka "Microsoft Office Information Disclosure Vulnerability".
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1039994 | third party advisory vdb entry |
http://www.securityfocus.com/bid/102105 | third party advisory vdb entry |
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11939 | patch vendor advisory issue tracking |