PT-2024-6793 · Microsoft · Office+1

Roy Lindholm

·

Published

2024-10-08

·

Updated

2024-11-07

·

CVE-2024-43576

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Office (affected versions not specified) Microsoft 365 Apps for Enterprise (affected versions not specified)
Description The issue is related to the use of an unreliable path search in Microsoft Office and Microsoft 365 Apps for Enterprise packages. Exploitation of this issue may allow an attacker to execute arbitrary code.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Untrusted Search Path

Weakness Enumeration

Related Identifiers

BDU:2024-08009
CVE-2024-43576

Affected Products

365 Apps For Enterprise
Office