CVE-2023-21721HighCVSS 6.5

Microsoft OneNote Elevation of Privilege Vulnerability

Published
February 14, 2023
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability? Any authenticated user could trigger this vulnerability. It does not require admin or other elevated privileges.

According to the CVSS metric, successful exploitation of this vulnerability could lead to total loss of integrity (I:H)? What does that mean for this vulnerability? An authenticated attacker could impersonate another user to perform actions.

How do I get the update for OneNote for Android? Please reference How to update the Play Store & apps on Android - Google Play Help for guidance.

🎯 Affected products1

  • Microsoft OneNote for Android

✅ Remediation

KBRelease Notes (Security Update) — fixed build 16.0.16026.20158

🔗 References (2)