PT-2023-3523 · Microsoft · Office+1

Ben Lichtman

·

Publicado

2023-07-11

·

Atualizado

2023-10-24

·

CVE-2023-33150

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Office versions prior to the fixed version
Description The issue is related to errors in security settings, allowing a remote attacker to bypass existing security restrictions. The vulnerability can be exploited if a filename ends in Extended ASCII 255 (NBSP), which can be written and read by Office, although it does not perform any actions with it. There have been reports of this issue being exploited in the wild, with some organizations still being vulnerable despite having August 2023 updates.
Recommendations For Microsoft Office versions prior to the fixed version, update to the latest version to resolve the issue. As a temporary workaround, consider restricting the use of filenames that end in Extended ASCII 255 (NBSP) to minimize the risk of exploitation.

Correção

Protection Mechanism Failure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-03734
CVE-2023-33150

Produtos afetados

Office
Office Word