PT-2023-3474 · Microsoft · Windows+6

Bahare Sabouri

+4

·

Published

2023-07-11

·

Updated

2026-03-01

·

CVE-2023-36884

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Office and Windows versions (affected versions not specified)
Description This issue is a remote code execution vulnerability affecting Microsoft Office and Windows systems. It stems from flaws in how input data is processed, specifically related to Office and Windows HTML. Successful exploitation allows attackers to execute arbitrary code remotely, potentially impacting the system. The vulnerability has been actively exploited in the wild by threat actors, including the RomCom (Storm-0978) group, who have used it to deploy Underground Ransomware. The vulnerability allows attackers to bypass Mark of the Web (MOTW) defenses. The exploitation involves a complex chain, potentially utilizing .search-ms files and CHM files. The vulnerability was initially identified as CVE-2023-36884 and has been exploited in targeted attacks against organizations in Europe and North America.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

LPE

DoS

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-03660
CVE-2023-36884

Affected Products

Office
Windows
Office Excel
Office Powerpoint
Office Publisher
Office Visio
Office Word