PT-2024-22268 · Microsoft · Office Excel
Iodn
·
Published
2024-03-06
·
Updated
2024-03-07
·
CVE-2024-28111
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Canarytokens versions prior to sha-c595a1f8
Description
The generation of CSV files for incident history in Canarytokens is vulnerable to a CSV Injection issue. This can be exploited by an attacker who discovers an HTTP-based Canarytoken, targeting the owner if they export the incident history to CSV and open it in a reader like Microsoft Excel. The impact of this issue could lead to code execution on the machine where the CSV file is opened.
Recommendations
For versions prior to sha-c595a1f8, update to version sha-c595a1f8 to resolve the issue. As a temporary workaround, consider avoiding the export of incident history to CSV or refrain from opening such files in reader applications until the update is applied.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Office Excel