[High Risk] Office and Windows HTML Remote Code Execution Vulnerability

 Vulnerability description

 Windows is an operating system developed by Microsoft Corporation, and Office is Microsoft's office suite, including commonly used office applications such as Word, Excel, PowerPoint, etc.

Due to incorrect handling of cross-protocol file navigation in affected Windows and Office products, when a user opens a maliciously constructed Microsoft Office document, the attacker can remotely execute arbitrary code on the user's host. It is recommended to update the vulnerability patch in time: https:/ /msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36884.

Vulnerability name Office and Windows HTML Remote Code Execution Vulnerability
Vulnerability type code injection
Discovery time 2023/7/12
Vulnerability Breadth wide
MPS number MPS-ve9m-zjrb
CVE number  CVE-2023-36884
CNVD number -


Sphere of influence

Microsoft Word@[2013 Service Pack 1, 2016]

Microsoft Office LTSC@[2021, 2021]

Windows Server@[2008, 2022]

Windows 10@[1607, 22H2]

Windows 11@[21H2, 22H2]

Microsoft Office@[2019, 2019]

Repair plan

It is recommended to update the vulnerability patch in time. Users can also mitigate this vulnerability by using Microsoft Defender for Office or modifying the registry. For details, please refer to the official document: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023 -36884

reference link

https://www.oscs1024.com/hd/MPS-ve9m-zjrb




About Murphy Security 

Murphy Security is a technology company that provides you with professional software supply chain security management. The core team comes from Baidu, Huawei, Wuyun and other enterprises. The company provides customers with a complete software supply chain security management platform, and provides software with a full life cycle around SBOM Security management, platform capabilities include software component analysis, source security management, container image detection, vulnerability intelligence early warning and commercial software supply chain access assessment and other products. Provide customers with complete control capabilities from supply chain asset identification management, risk detection, security control, and one-key repair.

Open source project: https://github.com/murphysecurity/murphysec/?sf=qbyj

The product can be integrated with various tools in the existing development process at a very low cost, including seamless integration with dozens of tools such as IDE, Gitlab, Bitbucket, Jenkins, Harbor, and Nexus.

Free code security detection tool:  https://www.oscs1024.com/hd/MPS-ve9m-zjrb
Free intelligence subscription: https://www.oscs1024.com/cm/?sf=qbyj


Guess you like

Origin blog.csdn.net/murphysec/article/details/131900197