PT-2023-2722 · Microsoft · 365 Apps For Enterprise+4
Rocco Calvi
+1
·
Published
2023-05-09
·
Updated
2024-05-29
·
CVE-2023-24953
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microsoft Excel (affected versions not specified)
Microsoft Office (affected versions not specified)
Microsoft 365 Apps for Enterprise (affected versions not specified)
Microsoft SharePoint (affected versions not specified)
Microsoft Office Online Server (affected versions not specified)
Description
The vulnerability is related to a buffer overflow in memory, allowing an attacker to execute arbitrary code. This issue can be exploited by remote attackers, potentially affecting the system.
Recommendations
For Microsoft Excel, consider applying the latest security updates to resolve the issue.
For Microsoft Office, ensure all components are updated to the latest version to mitigate the risk.
For Microsoft 365 Apps for Enterprise, apply the latest patches to fix the vulnerability.
For Microsoft SharePoint, update to the latest version to resolve the issue.
For Microsoft Office Online Server, ensure the server is updated with the latest security fixes.
As a temporary workaround, consider restricting access to sensitive features in Microsoft Excel until a patch is available.
Fix
RCE
Use After Free
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
365 Apps For Enterprise
Office Excel
Office
Office Online Server
Sharepoint Server