Microsoft Office Remote Code Execution Vulnerability
CVE-2024-43576
7.8HIGH
Summary
The Microsoft Office Remote Code Execution Vulnerability allows attackers to execute arbitrary code on systems running affected Microsoft Office products. This issue arises from improper validation of user input, which can be exploited through specially crafted documents. Successful exploitation enables the attacker to gain the same user rights as the logged-in user, posing a significant risk to confidential information and system integrity. Users are urged to apply security updates to mitigate potential threats related to this vulnerability.
Affected Version(s)
Microsoft 365 Apps for Enterprise 32-bit Systems 16.0.1
Microsoft Office LTSC 2024 32-bit Systems 1.0.0
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre DatabaseMicrosoft Feed