Input validation error in Microsoft products - CVE-2023-32029

 

Input validation error in Microsoft products - CVE-2023-32029

Published: June 13, 2023 / Updated: June 29, 2023


Vulnerability identifier: #VU77263
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-32029
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the system.

The vulnerability exists due to insufficient validation of user-supplied input in Microsoft Excel. A remote attacker can trick a victim to open a specially crafted file and execute arbitrary code on the target system.


Affected software

Office Online Server
Microsoft Office LTSC
Microsoft 365 Apps for Enterprise
Microsoft Excel
Microsoft Office

How to mitigate CVE-2023-32029

Install updates from vendor's website.

Microsoft 365 Apps for Enterprise - addressed in versions 2202 14931.21024, 2208 15601.20680, 2302 16130.20580, 2303 16227.20354, 2304 16327.20324, 2305 16501.20210
Microsoft Excel - addressed in versions 16.0.16327.20324, 16.0.16501.20210

External References

Related Security Bulletins