PT-2024-8776 · Microsoft · Office+4

Orange Tsai

+2

·

Published

2024-11-12

·

Updated

2024-11-16

·

CVE-2024-49026

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Microsoft Excel versions (affected versions not specified) Microsoft 365 Apps for Enterprise versions (affected versions not specified) Microsoft Office versions (affected versions not specified) Microsoft Office Long Term Servicing Channel versions (affected versions not specified) Microsoft Office Online Server versions (affected versions not specified)
Description: The issue is related to a lack of data sanitization at the management level in Microsoft Office packages, including Microsoft Excel. Exploitation of this issue may allow an attacker to execute arbitrary code using a specially crafted malicious file.
Recommendations: For Microsoft Excel, consider disabling the execution of external files until a patch is available. For Microsoft 365 Apps for Enterprise, restrict access to potentially vulnerable components to minimize the risk of exploitation. For Microsoft Office, Microsoft Office Long Term Servicing Channel, and Microsoft Office Online Server, avoid using potentially vulnerable features or modules until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-10392
CVE-2024-49026

Affected Products

365 Apps For Enterprise
Office Excel
Office
Office Long Term Servicing Channel
Office Online Server