Lucene search

K
cve[email protected]CVE-2007-6329
HistoryDec 13, 2007 - 7:46 p.m.

CVE-2007-6329

2007-12-1319:46:00
CWE-255
web.nvd.nist.gov
22
microsoft
office 2007
mso 12.0.6015.5000
ooxml
metadata
security vulnerability
cve-2007-6329
nvd

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

6.6 Medium

AI Score

Confidence

Low

0.726 High

EPSS

Percentile

98.1%

Microsoft Office 2007 12.0.6015.5000 and MSO 12.0.6017.5000 do not sign the metadata of Office Open XML (OOXML) documents, which makes it easier for remote attackers to modify Dublin Core metadata fields, as demonstrated by the (1) LastModifiedBy and (2) creator fields in docProps/core.xml in the OOXML ZIP container.

Affected configurations

NVD
Node
microsoftofficeMatch200712.0.6015.5000
OR
microsoftofficeMatch200712.0.6017.5000
CPENameOperatorVersion
microsoft:officemicrosoft officeeq2007

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

6.6 Medium

AI Score

Confidence

Low

0.726 High

EPSS

Percentile

98.1%

Related for CVE-2007-6329