Buffer overflow in Microsoft products - CVE-2023-33131

 

Buffer overflow in Microsoft products - CVE-2023-33131

Published: June 13, 2023 / Updated: October 25, 2024


Vulnerability identifier: #VU77236
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-33131
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when processing files. A remote attacker can create a specially crafted file, trick the victim into opening it, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Microsoft Office LTSC
Microsoft Outlook
Microsoft Office
Microsoft 365 Apps for Enterprise

How to mitigate CVE-2023-33131

Install updates from vendor's website.

Microsoft 365 Apps for Enterprise - addressed in versions 2304 16327.20324, 2305 16501.20210

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins