#VU79180 Spoofing attack in Microsoft products - CVE-2023-36897
Published: August 8, 2023 / Updated: August 10, 2023
Vulnerability identifier: #VU79180
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2023-36897
CWE-ID: CWE-451
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
Visual Studio 2010 Tools for Office Runtime
Visual Studio
Microsoft Office LTSC
Microsoft Office
Microsoft 365 Apps for Enterprise
Visual Studio 2010 Tools for Office Runtime
Visual Studio
Microsoft Office LTSC
Microsoft Office
Microsoft 365 Apps for Enterprise
Software vendor:
Microsoft
Microsoft
Description
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to incorrect processing of user-supplied data in Visual Studio Tools for Office. A remote attacker can spoof page content.
Remediation
Install updates from vendor's website.