CVE-2023-21716CriticalCVSS 9.8

Microsoft Word Remote Code Execution Vulnerability

Published
February 14, 2023
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

What is the attack vector for this vulnerability? An unauthenticated attacker could send a malicious e-mail containing an RTF payload that would allow them to gain access to execute commands within the application used to open the malicious file.

Is the Preview Pane an attack vector for this vulnerability? Yes, the Preview Pane is an attack vector.

I am running SharePoint Enterprise Server 2013 Service Pack 1. Do I need to install all the updates that are listed for SharePoint Enterprise Server 2013 Service Pack 1? No. Customers running SharePoint Enterprise Server 2013 Service Pack 1 should install either of the following: Cumulative update (ubersrv13). Note that this update also includes the *srvloc2013 update Both of the security updates (sts2013 AND *loc2013), which are the same updates as for Foundation Server 2013 Please note that this is a clarification of the existing servicing model for SharePoint Server 2013 and applies for all previous updates.

I am running SharePoint Foundation 2013 Service Pack 1. Do I need to install all the updates that are listed for SharePoint Foundation 2013 Service Pack 1 ? Yes, customers running SharePoint Foundation 2013 Service Pack 1 should install both of the security updates. The updates can be installed in any order.

🎯 Affected products21

  • Microsoft 365 Apps for Enterprise for 32-bit Systems
  • Microsoft 365 Apps for Enterprise for 64-bit Systems
  • Microsoft Office 2019 for 32-bit editions
  • Microsoft Office 2019 for 64-bit editions
  • Microsoft Office 2019 for Mac
  • Microsoft Office LTSC 2021 for 32-bit editions
  • Microsoft Office LTSC 2021 for 64-bit editions
  • Microsoft Office LTSC for Mac 2021
  • Microsoft Office Online Server
  • Microsoft Office Web Apps Server 2013 Service Pack 1
  • Microsoft SharePoint Enterprise Server 2013 Service Pack 1
  • Microsoft SharePoint Enterprise Server 2016
  • Microsoft SharePoint Foundation 2013 Service Pack 1
  • Microsoft SharePoint Server 2019
  • Microsoft SharePoint Server Subscription Edition
  • Microsoft Word 2013 RT Service Pack 1
  • Microsoft Word 2013 Service Pack 1 (32-bit editions)
  • Microsoft Word 2013 Service Pack 1 (64-bit editions)
  • Microsoft Word 2016 (32-bit edition)
  • Microsoft Word 2016 (64-bit edition)
  • SharePoint Server Subscription Edition Language Pack

✅ Remediation

KBRelease Notes (Security Update) — fixed build 16.70.23021201 KBClick to Run (Security Update) — fixed build https://aka.ms/OfficeSecurityReleases KB5002353 (Security Update) — fixed build 16.0.15601.20478 KB5002352 (Security Update) — fixed build 16.0.15601.20478 KB5002309 (Security Update) — fixed build 16.0.10395.20001 KB5002325 (Security Update) — fixed build 16.0.5383.1000 KB5002346 (Cumulative Update) — fixed build 15.0.5529.1000 KB5002347 (Security Update) — fixed build 15.0.5529.1000 KB5002312 (Security Update) — fixed build 15.0.5529.1000 KB5002342 (Security Update) — fixed build 16.0.10395.20001 KB5002330 (Security Update) — fixed build 16.0.10395.20001 KB5002323 (Security Update) — fixed build 16.0.5383.1000 KB5002313 (Security Update) — fixed build 15.0.5529.1000 KB5002316 (Security Update) — fixed build 15.0.5529.1000

🔗 References (30)