Incomplete list of disallowed inputs in Microsoft Office OneNote allows an unauthorized attacker to bypass a security feature locally.
The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Office | Microsoft | 2019 (including) | 2019 (including) |
| Office_long_term_servicing_channel | Microsoft | 2021 (including) | 2021 (including) |
| Office_long_term_servicing_channel | Microsoft | 2024 (including) | 2024 (including) |
| Onenote | Microsoft | - (including) | - (including) |
| Onenote | Microsoft | 2016 (including) | 2016 (including) |