CVE-2017-11939: Microsoft Office
Medium severity, CVSS 6.5. EPSS: 6.3% chance of exploitation in the next 30 days.
Microsoft Office 2016 Click-to-Run (C2R) allows an information disclosure vulnerability due to the way Microsoft Office enforces DRM copy/paste permissions, aka "Microsoft Office Information Disclosure Vulnerability".
Affected products
- Microsoft Office: version 2016 only
Published 2017-12-12. Last modified 2026-06-17.