VDB
CVE-2023-33148
CVE-2023-33148
PUBLISHED
In Microsoft 365 Apps, Microsoft Excel, Microsoft Office, Microsoft Office Online Server, Microsoft Outlook, Microsoft SharePoint und Microsoft Word existieren mehrere Schwachstellen. Diese werden von Microsoft nicht im Detail beschrieben. Ein Angreifer kann diese Schwachstellen ausnutzen, um seine Privilegien zu erweitern, beliebigen Programmcode auszuführen, Informationen offenzulegen, Sicherheitsvorkehrungen zu umgehen oder Dateien zu manipulieren. Zur Ausnutzung einiger dieser Schwachstellen ist eine Benutzeraktion erforderlich.
EPSS 1.72% · 82.7th percentile
Risk Scores
EPSS Score
1.72%
82.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Microsoft Excel 2016 | |
| Microsoft | Microsoft SharePoint Server 2019 | |
| Microsoft | Microsoft Outlook 2013 RT SP1 | |
| Microsoft | Microsoft Office 2013 RT SP1 | |
| Microsoft | Microsoft Excel 2013 SP1 | |
| Microsoft | Microsoft Outlook 2016 | |
| Microsoft | Microsoft Word 2013 SP1 | |
| Microsoft | Microsoft Word 2013 RT SP1 | |
| Microsoft | Microsoft 365 Apps | |
| Microsoft | Microsoft SharePoint Enterprise Server 2016 | |
| Microsoft | Microsoft Office LTSC 2021 | |
| Microsoft | Microsoft Outlook 2013 | |
| Microsoft | Microsoft Office 2013 Click-to-Run (C2R) | |
| Microsoft | Microsoft Office 2016 | |
| Microsoft | Microsoft Office Online Server | |
| Microsoft | Microsoft SharePoint Server Subscription Edition | |
| Microsoft | Microsoft Office for Universal | |
| Microsoft | Microsoft Excel 2013 RT SP1 | |
| Microsoft | Microsoft Office 2013 SP1 | |
| Microsoft | Microsoft Office 2019 for Mac |
…and 3 more
Exploit Intelligence
- https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1 (msrc)
- http://packetstormsecurity.com/files/173591/Microsoft-Office-365-18.2305.1222.0-Remote-Code-Execution.html (nist-nvd)
- Microsoft Office Elevation of Privilege Vulnerability (circl)
- https://packetstorm.news/files/id/173591 (cve.org)
- Microsoft Office 365 Version 18.2305.1222.0 - Elevation of Privilege + RCE. (remote) by nu11secur1ty (coalition_cess)
- Microsoft Office 365 Version 18.2305.1222.0 - Elevation of Privilege / Remote Code Execution (0day-today)
- Microsoft Office 365 Version 18.2305.1222.0 - Elevation of Privilege / Remote Code Execution (0day-today)
Timeline
- Jul 11, 2023 CVE Published
- Jul 12, 2023 EPSS Score
- Jul 21, 2023 PoC Published
- Aug 16, 2023 EPSS Score
- Sep 19, 2023 EPSS Score
- Oct 24, 2023 EPSS Score
- Jan 1, 2024 EPSS Score
- Feb 5, 2024 EPSS Score
- Mar 10, 2024 EPSS Score
- Apr 14, 2024 EPSS Score
- May 18, 2024 EPSS Score
- Jun 22, 2024 EPSS Score