PT-2023-2722 · Microsoft · 365 Apps For Enterprise+4

Rocco Calvi

+1

·

Published

2023-05-09

·

Updated

2024-05-29

·

CVE-2023-24953

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Excel (affected versions not specified) Microsoft Office (affected versions not specified) Microsoft 365 Apps for Enterprise (affected versions not specified) Microsoft SharePoint (affected versions not specified) Microsoft Office Online Server (affected versions not specified)
Description The vulnerability is related to a buffer overflow in memory, allowing an attacker to execute arbitrary code. This issue can be exploited by remote attackers, potentially affecting the system.
Recommendations For Microsoft Excel, consider applying the latest security updates to resolve the issue. For Microsoft Office, ensure all components are updated to the latest version to mitigate the risk. For Microsoft 365 Apps for Enterprise, apply the latest patches to fix the vulnerability. For Microsoft SharePoint, update to the latest version to resolve the issue. For Microsoft Office Online Server, ensure the server is updated with the latest security fixes. As a temporary workaround, consider restricting access to sensitive features in Microsoft Excel until a patch is available.

Fix

RCE

Use After Free

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-02567
CVE-2023-24953

Affected Products

365 Apps For Enterprise
Office Excel
Office
Office Online Server
Sharepoint Server