Information disclosure in Microsoft products - CVE-2023-36761
Published: September 12, 2023
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the application ca reveal sensitive information to a third-party. A remote attacker can trick the victim to open or preview a specially crafted file and obtain NTLM hash of the current account.
Note, the vulnerability is being actively exploited in the wild.
Affected software
Microsoft Word
Microsoft 365 Apps for Enterprise
How to mitigate CVE-2023-36761
Microsoft 365 Apps for Enterprise - addressed in versions 15.0.5589.1001, 16.0.5413.1000