Microsoft Office 2010 SP2, Microsoft Office 2013 SP1 and RT SP1, Microsoft Office 2016, and Microsoft Office 2016 Click-to-Run (C2R) allow an information disclosure vulnerability, due to how Office initializes the affected variable, aka "Microsoft Office Information Disclosure Vulnerability".
The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/102868 | third party advisory vdb entry |
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0853 | patch vendor advisory |
http://www.securitytracker.com/id/1040381 | third party advisory vdb entry |