Information disclosure in Microsoft products - CVE-2023-36761

 

Information disclosure in Microsoft products - CVE-2023-36761

Published: September 12, 2023


Vulnerability identifier: #VU80655
CSH Severity: High
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-36761
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to the application ca reveal sensitive information to a third-party. A remote attacker can trick the victim to open or preview a specially crafted file and obtain NTLM hash of the current account.

Note, the vulnerability is being actively exploited in the wild.


Affected software

Microsoft Office
Microsoft Word
Microsoft 365 Apps for Enterprise

How to mitigate CVE-2023-36761

Install updates from vendor's website.

Microsoft Word - addressed in versions 15.0.5589.1001, 16.0.5413.1000
Microsoft 365 Apps for Enterprise - addressed in versions 15.0.5589.1001, 16.0.5413.1000

External References

Related Security Bulletins