Input validation error in Microsoft products - CVE-2023-32029
Published: June 13, 2023 / Updated: June 29, 2023
Vulnerability identifier: #VU77263
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-32029
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the system.
The vulnerability exists due to insufficient validation of user-supplied input in Microsoft Excel. A remote attacker can trick a victim to open a specially crafted file and execute arbitrary code on the target system.
Affected software
Office Online Server
Microsoft Office LTSC
Microsoft 365 Apps for Enterprise
Microsoft Excel
Microsoft Office
Microsoft Office LTSC
Microsoft 365 Apps for Enterprise
Microsoft Excel
Microsoft Office
How to mitigate CVE-2023-32029
Install updates from vendor's website.
Microsoft 365 Apps for Enterprise - addressed in versions 2202 14931.21024, 2208 15601.20680, 2302 16130.20580, 2303 16227.20354, 2304 16327.20324, 2305 16501.20210
Microsoft Excel - addressed in versions 16.0.16327.20324, 16.0.16501.20210
Microsoft Excel - addressed in versions 16.0.16327.20324, 16.0.16501.20210