Gravedad: High
  Identificadores de CVE : CVE-2013-5054
  Fecha recomendada: 26 de diciembre de 2013

  Descripción

This security update resolves one privately reported vulnerability in Microsoft Office that could allow information disclosure if a user attempts to open an Office file hosted on a malicious website. An attacker who successfully exploited this vulnerability could ascertain access tokens used to authenticate the current user on a targeted SharePoint or other Microsoft Office server site.

  Soluciones

  Software y versión afectados

  • Microsoft Office 2013 (32-bit editions)
  • Microsoft Office 2013 R