Race condition in Microsoft products - CVE-2023-36565

 

Race condition in Microsoft products - CVE-2023-36565

Published: October 11, 2023 / Updated: November 13, 2024


Vulnerability identifier: #VU81859
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-36565
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a race condition in Microsoft Office Graphics. A local user can exploit the race and gain unauthorized access to sensitive information and escalate privileges on the system.


Affected software

Microsoft Office for Universal
Microsoft Office for Android
Microsoft Office LTSC

How to mitigate CVE-2023-36565

Install updates from vendor's website.

Microsoft Office for Universal - update to 16.0.14326.21606
Microsoft Office for Android - update to 16.0.16827.20138
Microsoft Office LTSC - update to 16.78 23100802

External References

Related Security Bulletins