Microsoft OneNote vulnerability could allow information disclosure
Report ID: MS201303005
Date Published: 13 March 2013
Criticality: Important
Compromise Type: information-disclosure
Compromise From: remote
Affected Product/Component:
Microsoft OneNote 2010
Summary
A vulnerability in Microsoft OneNote could expose sensitive information for a configured accounts to an attacker.
Detailed Description
Microsoft has released a security update to address a vulnerability in Microsoft OneNote. The vulnerability was caused by a buffer size validation issue; upon successful exploitation, an attacker could be able to view sensitive information such as the username and password of configured accounts.
This issue has been resolved in the latest security update by modifying the way Microsoft OneNote checks the size of a buffer. Users are recommended to install this update to protect their system from possible exploit attempts.
CVE Reference
CVE-2013-0086
Solution
Install the latest security patch for applicable system, available for download from (https://technet.microsoft.com/en-us/security/bulletin/ms13-025)
F-Secure Health Check
F-Secure's free tool, the Health Check, detects if your system is missing the patch for the vulnerability covered in this report.




