Microsoft Excel Security Feature Bypass Vulnerability
🔗 CVE IDs covered (1)
📋 Description
What kind of security feature could be bypassed by successfully exploiting this vulnerability? Opening a malicious file could bypass the Microsoft Office Trust Center external links check. External links can include Dynamic Data Exchange (DDE) and/or references to other workbooks. See Block or unblock external content in Office documents - Microsoft Support for descriptions of related Trust Center settings.
According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? An attacker must send the user a malicious file and convince them to open it.
According to the CVSS metrics, successful exploitation of this vulnerability could lead to major loss of confidentiality (C:H), integrity (I:H), and availability (A:H). What does that mean for this vulnerability? An attacker who successfully exploited this vulnerability could gain high privileges, which include read, write, and delete functionality.
🎯 Affected products9
- Microsoft 365 Apps for Enterprise for 32-bit Systems
- Microsoft 365 Apps for Enterprise for 64-bit Systems
- Microsoft Excel 2016 (32-bit edition)
- Microsoft Excel 2016 (64-bit edition)
- Microsoft Office 2019 for 32-bit editions
- Microsoft Office 2019 for 64-bit editions
- Microsoft Office LTSC 2021 for 32-bit editions
- Microsoft Office LTSC 2021 for 64-bit editions
- Microsoft Office LTSC for Mac 2021
✅ Remediation
KBClick to Run (Security Update) — fixed build https://aka.ms/OfficeSecurityReleases KBRelease Notes (Security Update) — fixed build 16.79.23111019 KB5002518 (Security Update) — fixed build 16.0.5422.1000
🔗 References (6)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36037
- referencehttps://docs.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates
- patchhttps://go.microsoft.com/fwlink/p/?linkid=831049
- patchhttps://www.microsoft.com/download/details.aspx?familyid=008cec1e-d63f-44b1-86ca-28a8c884c6cd
- referencehttps://support.microsoft.com/help/5002518
- patchhttps://www.microsoft.com/download/details.aspx?familyid=003f87de-8a7a-439d-905a-b534440265bb