ZeroHour
ZDI Published Advisoriespublished ()ingested 1

ZDI-26-607: Microsoft Office HTML Injection Information Disclosure Vulnerability

lowVulnerabilityimportance 18
AI summary · glm-5.3-flash

ZDI disclosed an HTML injection flaw in Microsoft Office (CVSS 7.6) that lets remote attackers disclose sensitive information via malicious pages or files.

Zero Day Initiative advisory ZDI-26-607 describes an HTML injection vulnerability in Microsoft Office that leads to information disclosure. Remote attackers need the target to visit a malicious page or open a malicious file to trigger it. ZDI rated the issue 7.6 on the CVSS scale and the advisory lists no CVE identifier. The advisory does not indicate active exploitation.

  • HTML injection in Microsoft Office enables sensitive information disclosure
  • Requires user interaction with malicious content
  • CVSS 7.6; no CVE id provided in the advisory
Full article

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft Office. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.6.

This source does not provide full text. Read it at zerodayinitiative.com.