PT-2023-2722 · Microsoft · 365 Apps For Enterprise+4
Rocco Calvi
+1
·
Publicado
2023-05-09
·
Atualizado
2024-05-29
·
CVE-2023-24953
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microsoft Excel (affected versions not specified)
Microsoft Office (affected versions not specified)
Microsoft 365 Apps for Enterprise (affected versions not specified)
Microsoft SharePoint (affected versions not specified)
Microsoft Office Online Server (affected versions not specified)
Description
The vulnerability is related to a buffer overflow in memory, allowing an attacker to execute arbitrary code. This issue can be exploited by remote attackers, potentially affecting the system.
Recommendations
For Microsoft Excel, consider applying the latest security updates to resolve the issue.
For Microsoft Office, ensure all components are updated to the latest version to mitigate the risk.
For Microsoft 365 Apps for Enterprise, apply the latest patches to fix the vulnerability.
For Microsoft SharePoint, update to the latest version to resolve the issue.
For Microsoft Office Online Server, ensure the server is updated with the latest security fixes.
As a temporary workaround, consider restricting access to sensitive features in Microsoft Excel until a patch is available.
Correção
RCE
Use After Free
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
365 Apps For Enterprise
Office Excel
Office
Office Online Server
Sharepoint Server