Description
Microsoft Office Remote Code Execution Vulnerability
CVSS breakdown
CVSS 3.1
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
E
Unchanged
RL
O
RC
Changed
Affected products
- microsoft / Microsoft 365 Apps for Enterprise16.0.1 – https://aka.ms/OfficeSecurityReleases
- microsoft / Microsoft Office 2019 for Mac16.0.0 – 16.72.23040900
- microsoft / Microsoft Office LTSC for Mac 202116.0.1 – 16.72.23040900
Exploits & proofs of concept
- exploit-dbMicrosoft 365 MSO (Version 2305 Build 16.0.16501.20074) 64-bit - Remote Code Execution (RCE)by nu11secur1ty
References
Updated 18m ago · 8 sources