VDB
CVE-2023-29335
CVE-2023-29335
PUBLISHED
Es existiert eine Schwachstelle in Microsoft 365 Apps, Microsoft Excel 2013, Microsoft Office, Microsoft Office 2019, Microsoft Office 2019 for Mac, Microsoft Word 2013 und Microsoft Word 2016. Microsoft veröffentlicht keine weiteren Details zur Schwachstelle. Ein entfernter, anonymer Angreifer kann diese Schwachstelle ausnutzen, um Sicherheitsvorkehrungen zu umgehen. Zur erfolgreichen Ausnutzung ist eine Benutzeraktion erforderlich.
EPSS 0.59% · 69.6th percentile
Risk Scores
EPSS Score
0.59%
69.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Microsoft Office 2019 | |
| Microsoft | Microsoft Office 2019 for Mac | |
| Microsoft | Microsoft Office LTSC for Mac 2021 | |
| Microsoft | Microsoft Office LTSC 2021 | |
| Microsoft | Microsoft Word 2013 SP1 | |
| Microsoft | Microsoft Word 2013 RT SP1 | |
| Microsoft | Microsoft Word 2016 | |
| Microsoft | Microsoft 365 Apps | |
| Microsoft | Microsoft Excel 2013 RT SP1 |
Exploit Intelligence
- https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1 (msrc)
- https://thehackernews.com/2024/01/act-now-cisa-flags-active-exploitation.html (certbund)
- risk_calculator.cpp (github-poc)
- risk_calculator.cpp (github-poc)
- risk_calculator.cpp (github-poc)
- risk_calculator.cpp (github-poc)
- risk_calculator.cpp (github-poc)
- risk_calculator.cpp (github-poc)
- risk_calculator.cpp (github-poc)
- risk_calculator.cpp (github-poc)
Timeline
- May 9, 2023 CVE Published
- May 10, 2023 EPSS Score
- Jun 16, 2023 EPSS Score
- Jul 23, 2023 EPSS Score
- Oct 4, 2023 EPSS Score
- Nov 10, 2023 EPSS Score
- Dec 17, 2023 EPSS Score
- Jan 22, 2024 EPSS Score
- Feb 28, 2024 EPSS Score
- May 12, 2024 EPSS Score
- Jun 17, 2024 EPSS Score
- Jul 24, 2024 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-1179.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-1179 advisory
- https://msrc.microsoft.com/update-guide advisory
- https://thehackernews.com/2024/01/act-now-cisa-flags-active-exploitation.html exploit