CVE-2017-0195 PUBLISHED CVSS 5.400000095367432 MEDIUM

Microsoft Excel Services on Microsoft SharePoint Server 2010 SP1 and SP2, Microsoft Excel Web Apps 2010 SP2, Microsoft Office Web Apps 2010 SP2, Microsoft Office Web Apps Server 2013 SP1 and Office Online Server allows remote attackers to perform cross-site scripting and run script with local user privileges via a crafted request, aka "Microsoft Office XSS Elevation of Privilege Vulnerability."

EPSS 0.96% · 76.3th percentile

Risk Scores

CVSS v3.0
5.400000095367432
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS Score
0.96%
76.3th percentile

Affected Products

VendorProductVersions
microsoftoffice_online_server
Microsoft CorporationOfficeExcel Services on Microsoft SharePoint Server 2010 SP1 and SP2, Microsoft Excel Web Apps 2010 SP2, Microsoft Office Web Apps 2010 SP2, Microsoft Office Web Apps Server 2013 SP1, and Office Online Server
microsoftoffice_web_apps_server2013
microsoftexcel_web_app2010
microsoftsharepoint_server2010, 2010
microsoftoffice_web_apps2010

Timeline

References

Open in Interactive Console →