This security update resolves a spoofing vulnerability that exists if Office Online does not validate the origin in cross-origin communications correctly. To learn more about the vulnerability, see Microsoft Common Vulnerabilities and Exposures CVE-2020-0647.
Note To apply this security update, you must have the release version of Microsoft Office Online Server installed on the computer.
Known issues in this update
-
After you install this security update, Office Online Server logging will be set to Verbose by default. We recommend that you change this setting to Medium by running the following command:
Set-OfficeWebAppsFarm -LogVerbosity “Medium”
Note After you run the command, you have to restart the Office Online Service. To do this, run the following command:
Restart-Service WACSM