VDB

GCVE-110-NCSC-2024-365

GCVE-110-NCSC-2024-365
Advisory PublishedCVSS 7.2/10
Vulnetix · Advisory published September 10, 2024
Microsoft heeft kwetsbaarheden verholpen in diverse Office producten.

Weaknesses (CWE)

CWE-502Deserialization of Untrusted DataCWE-77Improper Neutralization of Special Elements used in a Command ('Command Injection')CWE-126Buffer Over-readCWE-416Use After FreeCWE-693Protection Mechanism FailureCWE-285Improper AuthorizationCWE-284Improper Access Control

Risk Scores

CVSS 3.1
7.2/10
High · CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Affected Products

VendorProductVersionsPlatforms
microsoftmicrosoft_office_for_universal
microsoftmicrosoft_publisher_2016
microsoftmicrosoft_365_apps_for_enterprise
microsoftmicrosoft_office_2019
microsoftmicrosoft_office_ltsc_2021
microsoftmicrosoft_office_online_server
microsoftmicrosoft_sharepoint_enterprise_server_2016
microsoftmicrosoft_excel_2016
microsoftmicrosoft_visio_2016
microsoftoutlook_for_ios
microsoftmicrosoft_autoupdate_for_mac
microsoftmicrosoft_office_for_android
microsoftmicrosoft_office_ltsc_for_mac_2021
microsoftmicrosoft_sharepoint_server_subscription_edition
microsoftmicrosoft_sharepoint_server_2019

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›