Description
Incomplete list of disallowed inputs in Microsoft Office OneNote allows an unauthorized attacker to bypass a security feature locally.
CVSS breakdown
CVSS 3.1
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
E
Unchanged
RL
O
RC
Changed
Affected products
- Microsoft / Microsoft 365 Apps for Enterprise16.0.1 – https://aka.ms/OfficeSecurityReleases
- Microsoft / Microsoft Office 201919.0.0 – https://aka.ms/OfficeSecurityReleases
- Microsoft / Microsoft Office LTSC 202116.0.1 – https://aka.ms/OfficeSecurityReleases
- Microsoft / Microsoft Office LTSC 202416.0.0 – https://aka.ms/OfficeSecurityReleases
- Microsoft / Microsoft Office LTSC for Mac 202116.0.1 – 16.96.25041326
- Microsoft / Microsoft Office LTSC for Mac 202416.0.0 – 16.96.25041326
- Microsoft / Microsoft OneNote1.0.0 – 16.96.25033028
- Microsoft / Microsoft OneNote 201616.0.0 – 16.0.5495.1001