Deserialization of untrusted data in Microsoft Office allows an unauthorized attacker to elevate privileges locally.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
365_apps | Microsoft | - (including) | - (including) |
Office | Microsoft | 2016 (including) | 2016 (including) |
Office | Microsoft | 2019 (including) | 2019 (including) |
Office_long_term_servicing_channel | Microsoft | 2021 (including) | 2021 (including) |
Office_long_term_servicing_channel | Microsoft | 2024 (including) | 2024 (including) |
Sharepoint_enterprise_server | Microsoft | 2016 (including) | 2016 (including) |