A spoofing vulnerability exists when an Office Web Apps server does not properly sanitize a specially crafted request, aka 'Office Web Apps XSS Vulnerability'.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Microsoft Office | — | Download and install Microsoft KB4484451 | Jul 11, 2023 | Jul 14, 2020 |
| Msft | — | Security Update for Microsoft Office Web Apps Server 2013 (KB4484357)Security Update for Microsoft Office Online Server (KB4484451) farm-deployment | Jul 14, 2020 | Jul 14, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub