CVE-2020-0695: Microsoft Office Online Server Spoofing Vulnerability

Overview

Severity
N/A
Category
Spoofing
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2020-Feb
Released
2020-02-11
EPSS Score
0.79% (percentile: 73.9%)

Description

A spoofing vulnerability exists when Office Online Server does not validate origin in cross-origin communications correctly. An attacker could exploit the vulnerability by sending a specially crafted request to an affected site. The attacker who successfully exploited the vulnerability could then perform cross-origin attacks on affected systems. These attacks could allow the attacker to read content that the attacker is not authorized to read, and use the victim's identity to take actions on the site on behalf of the victim. The victim needs to be authenticated for an attacker to compromise the victim. The security update addresses the vulnerability by ensuring that Office Online Server properly validates origins.

FAQ

Is the Preview Pane an attack vector for this vulnerability? No, the Preview Pane is not an attack vector.

Affected Products (1)

Microsoft Office

  • Office Online Server

Security Updates (1)

Acknowledgments

SURESH C

Revision History

  • 2020-02-11: Information published.