Microsoft Office 2010 SP2, Microsoft Office 2013 SP1 and RT SP1, Microsoft Office 2016, and Microsoft Office 2016 Click-to-Run (C2R) allow an information disclosure vulnerability, due to how Office initializes the affected variable, aka Microsoft Office Information Disclosure Vulnerability.
The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Office | Microsoft | 2010-sp2 (including) | 2010-sp2 (including) |
Office | Microsoft | 2013-sp1 (including) | 2013-sp1 (including) |
Office | Microsoft | 2016 (including) | 2016 (including) |