CVE ID | |
CVSS SCORE | 4.3, AV:N/AC:M/Au:N/C:N/I:N/A:P |
AFFECTED VENDORS |
Microsoft |
AFFECTED PRODUCTS |
Office Word |
VULNERABILITY DETAILS |
The specific flaw exists within the line formatting functionality. By providing a malformed .docx file, an attacker can cause a denial of service condition for the current user. |
ADDITIONAL DETAILS |
08/04/2014 - Report sent to vendor -- Vendor Mitigation: The vendor did not provide any mitigations. -- Mitigation: Given the stated purpose of Microsoft Word, and the nature of the vulnerability, the only salient mitigation strategy is to restrict interaction with the application to trusted files.
|
DISCLOSURE TIMELINE |
|
CREDIT | Alisa Esage |