Microsoft Office 2007 Groove Security Bypass / Code Execution

Discussion in 'News Aggregator' started by Packet Storm, 2 Oct 2017.

  1. Packet Storm

    Packet Storm Guest

    Microsoft Office 2007 Groove contains a security bypass issue regarding 'Workspace Shortcut' files (.GLK) because it allows arbitrary (registered) URL Protocols to be passed, when only 'grooveTelespace://' URLs should be allowed, which allows execution of arbitrary code upon opening a 'GLK' file.

    Continue reading...
     

Share This Page

Loading...