Vulnerability Name: | CVE-2007-6329 (CCN-39021) | ||||||||
Assigned: | 2007-12-13 | ||||||||
Published: | 2007-12-13 | ||||||||
Updated: | 2018-10-15 | ||||||||
Summary: | Microsoft Office 2007 12.0.6015.5000 and MSO 12.0.6017.5000 do not sign the metadata of Office Open XML (OOXML) documents, which makes it easier for remote attackers to modify Dublin Core metadata fields, as demonstrated by the (1) LastModifiedBy and (2) creator fields in docProps/core.xml in the OOXML ZIP container. | ||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 6.4 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N) 5.2 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N/E:U/RL:U/RC:UR)
1.7 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:U/RC:UR)
| ||||||||
Vulnerability Type: | CWE-255 | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Thu Dec 13 2007 - 09:07:09 CST MS Office 2007: Target of Hyperlinks not covered by Digital Signatures Source: MITRE Type: CNA CVE-2007-6329 Source: OSVDB Type: UNKNOWN 44938 Source: SREASON Type: UNKNOWN 3443 Source: CCN Type: OSVDB ID: 44938 Microsoft Office Open XML (OOXML) Document Metadata Field Modification Signature Weakness Source: BUGTRAQ Type: UNKNOWN 20071212 MS Office 2007: Digital Signature does not protect Meta-Data Source: BID Type: UNKNOWN 26833 Source: CCN Type: BID-26833 Microsoft Office Insecure Document Signing Weakness Source: XF Type: UNKNOWN microsoftoffice-xml-weak-security(39021) Source: XF Type: UNKNOWN microsoftoffice-xml-weak-security(39021) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |