This security update resolves a spoofing vulnerability that exists when Office Online does not validate origin in cross-origin communications handlers correctly. To learn more about the vulnerability, see the following security advisories:
- Microsoft Common Vulnerabilities and Exposures CVE-2019-1445
- Microsoft Common Vulnerabilities and Exposures CVE-2019-1446
- Microsoft Common Vulnerabilities and Exposures CVE-2019-1447
Note To apply this security update, you must have the release version of Microsoft Office Online Server installed on the computer.
Known issues in this update
-
After you install this security update, Office Online Server logging will be set to Verbose by default. We recommend that you change this setting to Medium by running the following command:
Set-OfficeWebAppsFarm -LogVerbosity “Medium”
Note After you run the command, you have to restart the Office Online Service. To do this, run the following command:
Restart-Service WACSM