VDB
GCVE-110-NCSC-2024-365
GCVE-110-NCSC-2024-365
Advisory PublishedCVSS 7.2/10
Microsoft heeft kwetsbaarheden verholpen in diverse Office producten.
Weaknesses (CWE)
CWE-502Deserialization of Untrusted DataCWE-77Improper Neutralization of Special Elements used in a Command ('Command Injection')CWE-126Buffer Over-readCWE-416Use After FreeCWE-693Protection Mechanism FailureCWE-285Improper AuthorizationCWE-284Improper Access Control
Risk Scores
CVSS 3.1
7.2/10
High · CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| microsoft | microsoft_office_for_universal | — | — |
| microsoft | microsoft_publisher_2016 | — | — |
| microsoft | microsoft_365_apps_for_enterprise | — | — |
| microsoft | microsoft_office_2019 | — | — |
| microsoft | microsoft_office_ltsc_2021 | — | — |
| microsoft | microsoft_office_online_server | — | — |
| microsoft | microsoft_sharepoint_enterprise_server_2016 | — | — |
| microsoft | microsoft_excel_2016 | — | — |
| microsoft | microsoft_visio_2016 | — | — |
| microsoft | outlook_for_ios | — | — |
| microsoft | microsoft_autoupdate_for_mac | — | — |
| microsoft | microsoft_office_for_android | — | — |
| microsoft | microsoft_office_ltsc_for_mac_2021 | — | — |
| microsoft | microsoft_sharepoint_server_subscription_edition | — | — |
| microsoft | microsoft_sharepoint_server_2019 | — | — |
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.