Microsoft OneNote Information Disclosure Vulnerability
CVE-2016-3315

5.5MEDIUM

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
9 August 2016

Summary

A vulnerability exists in Microsoft OneNote that could allow remote attackers to access sensitive information through specially crafted OneNote files. This vulnerability affects multiple versions of OneNote, including 2007 SP3, 2010 SP2, 2013 SP1, and the 2016 editions—highlighting the importance of applying the latest security updates to protect against unauthorized data access.

References

EPSS Score

45% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.