Deserialization of untrusted data in Microsoft Office allows an unauthorized attacker to elevate privileges locally.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| 365_apps | Microsoft | - (including) | - (including) |
| Office | Microsoft | 2016 (including) | 2016 (including) |
| Office | Microsoft | 2019 (including) | 2019 (including) |
| Office_long_term_servicing_channel | Microsoft | 2021 (including) | 2021 (including) |
| Office_long_term_servicing_channel | Microsoft | 2024 (including) | 2024 (including) |
| Sharepoint_enterprise_server | Microsoft | 2016 (including) | 2016 (including) |