Buffer overflow in Microsoft Office and Microsoft Word - CVE-2023-21716
Published: February 14, 2023 / Updated: November 22, 2024
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when processing RTF files. A remote attacker can create a specially crafted RTF document, trick the victim into opening it, trigger memory corruption and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Microsoft Word
How to mitigate CVE-2023-21716
Links to Public Exploits and PoC-codes
- Exploit #10893 - CVE-Vulnerability-Research (This repository focuses on exploring Common Vulnerabilities and Exposures (CVE), a standardized system for identifying and cataloging known cybersecurity vulnerabilities. It includes in-depth research on CVE impacts, exploitati (November 22, 2024)
- Exploit #10781 - poc-cve-2023-21716 (POC CVE 2023-21716) (October 30, 2024)
- Exploit #10099 - CVE-2023-21716 (A vulnerability within Microsoft Office's wwlib allows attackers to achieve remote code execution with the privileges of the victim that opens a malicious RTF document. The attacker could deliver this file as an email attachment (or other (June 21, 2024)
- Exploit #8936 - CVE-2023-21716_exploit (test of exploit for CVE-2023-21716) (March 25, 2023)
- Exploit #8888 - Microsoft Word RTF Font Table Heap Corruption (March 7, 2023)