PT-2023-8134 · Microsoft · Office +8

Hao Li

+2

·

Published

2023-07-13

·

Updated

2024-10-08

·

CVE-2024-20677

CVSS v3.1
7.8
VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Office versions prior to the January 9, 2024 security update Office 2019 Office 2021 Office LTSC for Mac 2021 Microsoft 365
Description A security issue exists in FBX that could lead to remote code execution. The vulnerability is related to errors in processing input data, which can be exploited by opening a specially crafted malicious file. To mitigate this issue, the ability to insert FBX files has been disabled in Word, Excel, PowerPoint, and Outlook for Windows and Mac. 3D models in Office documents that were previously inserted from a FBX file will continue to work as expected unless the Link to File option was chosen at insert time.
Recommendations For Office 2019, disable the ability to insert FBX files. For Office 2021, disable the ability to insert FBX files. For Office LTSC for Mac 2021, disable the ability to insert FBX files. For Microsoft 365, disable the ability to insert FBX files. As a temporary workaround, consider avoiding the use of FBX files in Office applications until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Heap Based Buffer Overflow

RCE

Use After Free

Weakness Enumeration

Related Identifiers

BDU:2024-00116
CVE-2024-20677
ZDI-24-030

Affected Products

Office Excel
365
Office
Office 2019
Office 2021
Office Ltsc For Mac 2021
Outlook
Office Powerpoint
Office Word