PT-2023-5037 · Microsoft · Office Word
Published
2023-09-12
·
Updated
2024-06-21
·
CVE-2023-36761
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Word versions prior to the fixed version in September 2023 Patch Tuesday
Description
The vulnerability in Microsoft Word is related to the lack of protection for internal data, which can allow an attacker to disclose sensitive information. Exploitation of this issue is not limited to opening a malicious Word document, as simply previewing the file can trigger the exploit. This can lead to the disclosure of New Technology LAN Manager (NTLM) hashes. The estimated number of potentially affected devices worldwide is not specified. However, it is mentioned that the vulnerability is being exploited in the wild.
Recommendations
As a temporary workaround, consider disabling the preview feature in Microsoft Word until a patch is available.
Update Microsoft Word to the version released in September 2023 Patch Tuesday or later.
Restrict access to sensitive information and limit the use of Microsoft Word for handling confidential documents until the issue is resolved.
Apply the patches provided by Microsoft in the September 2023 Patch Tuesday update to fix the vulnerability.
Fix
RCE
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Office Word