Spoofing attack in Microsoft products - CVE-2023-36897
Published: August 8, 2023 / Updated: August 10, 2023
Vulnerability identifier: #VU79180
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2023-36897
CWE-ID: CWE-451
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: Microsoft
Affected software:
Visual Studio 2010 Tools for Office Runtime
Visual Studio
Microsoft Office LTSC
Microsoft Office
Microsoft 365 Apps for Enterprise
Visual Studio 2010 Tools for Office Runtime
Visual Studio
Microsoft Office LTSC
Microsoft Office
Microsoft 365 Apps for Enterprise
Detailed vulnerability description
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to incorrect processing of user-supplied data in Visual Studio Tools for Office. A remote attacker can spoof page content.
How to mitigate CVE-2023-36897
Install updates from vendor's website.