Race condition in Microsoft products - CVE-2023-36565
Published: October 11, 2023 / Updated: November 13, 2024
Vulnerability identifier: #VU81859
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-36565
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a race condition in Microsoft Office Graphics. A local user can exploit the race and gain unauthorized access to sensitive information and escalate privileges on the system.
Affected software
Microsoft Office for Universal
Microsoft Office for Android
Microsoft Office LTSC
Microsoft Office for Android
Microsoft Office LTSC
How to mitigate CVE-2023-36565
Install updates from vendor's website.
Microsoft Office for Universal - update to 16.0.14326.21606
Microsoft Office for Android - update to 16.0.16827.20138
Microsoft Office LTSC - update to 16.78 23100802
Microsoft Office for Android - update to 16.0.16827.20138
Microsoft Office LTSC - update to 16.78 23100802