MEDIUM · 5.4

CVE-2017-0195

Microsoft Excel Services on Microsoft SharePoint Server 2010 SP1 and SP2, Microsoft Excel Web Apps 2010 SP2, Microsoft Office Web Apps 2010 SP2, Microsoft Office Web Apps Server 2013 SP1 and Office On...

Vulnerability Description

Microsoft Excel Services on Microsoft SharePoint Server 2010 SP1 and SP2, Microsoft Excel Web Apps 2010 SP2, Microsoft Office Web Apps 2010 SP2, Microsoft Office Web Apps Server 2013 SP1 and Office Online Server allows remote attackers to perform cross-site scripting and run script with local user privileges via a crafted request, aka "Microsoft Office XSS Elevation of Privilege Vulnerability."

CVSS Score

5.4

MEDIUM

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
MicrosoftExcel Web App2010
MicrosoftOffice Online ServerAll versions
MicrosoftOffice Web Apps2010
MicrosoftOffice Web Apps Server2013
MicrosoftSharepoint Server2010

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-0195?

CVE-2017-0195 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Microsoft Excel Services on Microsoft SharePoint Server 2010 SP1 and SP2, Microsoft Excel Web Apps 2010 SP2, Microsoft Office Web Apps 2010 SP2, Microsoft Office Web Apps Server 2013 SP1 and Office On...

How severe is CVE-2017-0195?

CVE-2017-0195 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2017-0195?

Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Excel Web App, Microsoft Office Online Server, Microsoft Office Web Apps, Microsoft Office Web Apps Server, Microsoft Sharepoint Server.