Microsoft Office Security Feature Bypass Vulnerability
🔗 CVE IDs covered (1)
📋 Description
According to the CVSS metric, the attack vector is local (AV:L) but no privileges are required (PR:N) and user interaction is required (UI:R). How could an attacker exploit this security feature bypass vulnerability? The attack itself is carried out locally by a user with authentication to the targeted system. An attacker could exploit the vulnerability by convincing a victim, through social engineering, to download and open a specially crafted file from a website which could lead to a local attack on the victim computer.
According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires an attacker to gather information specific to the environment of the targeted component.
🎯 Affected products11
- Microsoft 365 Apps for Enterprise for 32-bit Systems
- Microsoft 365 Apps for Enterprise for 64-bit Systems
- Microsoft Office 2013 RT Service Pack 1
- Microsoft Office 2013 Service Pack 1 (32-bit editions)
- Microsoft Office 2013 Service Pack 1 (64-bit editions)
- Microsoft Office 2016 (32-bit edition)
- Microsoft Office 2016 (64-bit edition)
- Microsoft Office 2019 for 32-bit editions
- Microsoft Office 2019 for 64-bit editions
- Microsoft Office LTSC 2021 for 32-bit editions
- Microsoft Office LTSC 2021 for 64-bit editions
✅ Remediation
KBClick to Run (Security Update) — fixed build https://aka.ms/OfficeSecurityReleases KB5002112 (Security Update) — fixed build 16.0.5344.1000 KB5002121 (Security Update) — fixed build 15.0.5467.1000
🔗 References (10)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-33632
- referencehttps://docs.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates
- patchhttps://www.microsoft.com/download/details.aspx?familyid=447b2ed3-8c9f-4abb-8eed-6c5311e53e74
- referencehttps://support.microsoft.com/kb/5002112
- referencehttps://support.microsoft.com/help/5002112
- patchhttps://www.microsoft.com/download/details.aspx?familyid=1cc4d651-5e50-4bac-8125-d5be09e6a755
- referencehttps://support.microsoft.com/kb/5002121
- referencehttps://support.microsoft.com/help/5002121
- patchhttps://www.microsoft.com/download/details.aspx?familyid=c91fa4d6-3069-4870-a58c-9f9b8e3e871a
- patchhttps://www.microsoft.com/download/details.aspx?familyid=28345644-ce93-4dd5-91c2-2bcc738edeaa