CVE-2023-36897HighCVSS 8.1

Visual Studio Tools for Office Runtime Spoofing Vulnerability

Published
August 8, 2023
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? The user would have to click on install to be compromised by the attacker.

How could an attacker exploit this vulnerability? An unauthenticated attacker could bypass validation as a trusted source through a crafted certificate that could mislead a user to believing the file they are installing is legitimate.

🎯 Affected products12

  • Microsoft 365 Apps for Enterprise for 32-bit Systems
  • Microsoft 365 Apps for Enterprise for 64-bit Systems
  • Microsoft Office 2019 for 32-bit editions
  • Microsoft Office 2019 for 64-bit editions
  • Microsoft Office LTSC 2021 for 32-bit editions
  • Microsoft Office LTSC 2021 for 64-bit editions
  • Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8)
  • Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)
  • Microsoft Visual Studio 2022 version 17.2
  • Microsoft Visual Studio 2022 version 17.4
  • Microsoft Visual Studio 2022 version 17.6
  • Visual Studio 2010 Tools for Office Runtime

✅ Remediation

KBClick to Run (Security Update) — fixed build https://aka.ms/OfficeSecurityReleases KBRelease Notes (Security Update) — fixed build 15.9.56 KBRelease Notes (Security Update) — fixed build 17.2.18 KBRelease Notes (Security Update) — fixed build 16.11.29 KBRelease Notes (Security Update) — fixed build 17.4.10 KBRelease Notes (Security Update) — fixed build 17.6.6 KB5029497 (Security Update) — fixed build 10.0.60910

🔗 References (13)