Eng
  1. Skip to navigation
  2. Skip to content
  3. Skip to sidebar


Vulnerability protection

Microsoft OneNote vulnerability could allow information disclosure


Report ID: MS201303005
Date Published: 13 March 2013

Criticality: Important
Compromise Type: information-disclosure
Compromise From: remote


Affected Product/Component:

Microsoft OneNote 2010




Summary

A vulnerability in Microsoft OneNote could expose sensitive information for a configured accounts to an attacker.



Detailed Description

Microsoft has released a security update to address a vulnerability in Microsoft OneNote. The vulnerability was caused by a buffer size validation issue; upon successful exploitation, an attacker could be able to view sensitive information such as the username and password of configured accounts.

This issue has been resolved in the latest security update by modifying the way Microsoft OneNote checks the size of a buffer. Users are recommended to install this update to protect their system from possible exploit attempts.



CVE Reference

CVE-2013-0086



Solution

Install the latest security patch for applicable system, available for download from (https://technet.microsoft.com/en-us/security/bulletin/ms13-025)



Security Advisories

For a list of known vulnerabilities affecting F-Secure products and the released fixes, please refer to the Security Advisories page.