VDB
CVE-2023-21717
CVE-2023-21717
PUBLISHED
In verschiedenen Microsoft Office und SharePoint Produkten existieren mehrere Schwachstellen. Ein Angreifer kann dadurch seine Privilegien auf SYSTEM Rechte ausweiten, beliebigen Code zur Ausführung bringen, Sicherheitsmechanismen umgehen und Informationen offenlegen. Für die Ausnutzung einiger Schwachstellen ist eine Benutzeraktion erforderlich.
EPSS 11.39% · 93.7th percentile
Risk Scores
EPSS Score
11.39%
93.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Microsoft OneNote for Android | |
| Microsoft | Microsoft SharePoint Server 2019 | |
| Microsoft | Microsoft SharePoint Server Subscription Edition Language Pack | |
| Microsoft | Microsoft Word 2016 | |
| Microsoft | Microsoft Office LTSC for Mac 2021 | |
| Microsoft | Microsoft SharePoint Enterprise Server 2016 | |
| Microsoft | Microsoft SharePoint Server Subscription Edition | |
| Microsoft | Microsoft 365 Apps | |
| Microsoft | Microsoft SharePoint Enterprise Server 2013 SP1 | |
| Microsoft | Microsoft Office LTSC 2021 | |
| Microsoft | Microsoft Word 2013 SP1 | |
| Microsoft | Microsoft Office for Universal | |
| Microsoft | Microsoft Office for Android | |
| Microsoft | Microsoft Office Online Server | |
| Microsoft | Microsoft Office Web Apps Server 2013 SP1 | |
| Microsoft | Microsoft Word 2013 RT SP1 | |
| Microsoft | Microsoft Office 2019 for Mac | |
| Microsoft | Microsoft Office for iOS | |
| Microsoft | Microsoft SharePoint Foundation 2013 SP1 |
Exploit Intelligence
- https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1 (msrc)
- Microsoft SharePoint Server Elevation of Privilege Vulnerability (circl)
- https://www.helpnetsecurity.com/2023/03/06/cve-2023-21716-poc/ (certbund)
- HUNT_RTF_CVE_2023_21716.yar (github-yara)
- SECUINFRA_HUNT_RTF_CVE_2023_21716_Mar23.yar (github-yara)
- CVE_2023_21716.yar (github-yara)
- CVE_2023_21716.yar (github-yara)
- CVE_2023_21716.yar (github-yara)
- CVE_2023_21716.yar (github-yara)
- HUNT_RTF_CVE_2023_21716.yar (github-yara)
…and 23 more exploits
Timeline
- Feb 14, 2023 CVE Published
- Feb 15, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 7, 2023 PoC Published
- Mar 27, 2023 EPSS Score
- Jun 14, 2023 EPSS Score
- Jul 24, 2023 EPSS Score
- Sep 1, 2023 EPSS Score
- Oct 11, 2023 EPSS Score
- Nov 20, 2023 EPSS Score
- Dec 29, 2023 EPSS Score
- Mar 1, 2024 PoC Published