PT-2022-5518 · Microsoft · 365 Apps For Enterprise+5
Rocco Calvi
+1
·
Published
2022-11-08
·
Updated
2026-05-19
·
CVE-2022-41061
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microsoft Office (affected versions not specified)
Microsoft 365 Apps for Enterprise (affected versions not specified)
Microsoft SharePoint (affected versions not specified)
Microsoft Excel (affected versions not specified)
Microsoft Office Web Apps Server (affected versions not specified)
Microsoft Word (affected versions not specified)
Description
The issue exists due to insufficient input validation in Microsoft products. It allows a remote attacker to execute arbitrary code. There is no information provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations
For Microsoft Office, consider disabling features that allow remote code execution until a patch is available.
For Microsoft 365 Apps for Enterprise, restrict access to vulnerable components to minimize the risk of exploitation.
For Microsoft SharePoint, avoid using vulnerable modules until the issue is resolved.
For Microsoft Excel, consider temporarily disabling the execution of arbitrary code.
For Microsoft Office Web Apps Server, restrict access to vulnerable API endpoints.
For Microsoft Word, consider disabling the ability to execute remote code until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
365 Apps For Enterprise
Office Excel
Office
Office Web Apps Server
Sharepoint Server
Office Word