Multiple vulnerabilities in Microsoft Excel

Published: 2023-06-13

Security Bulletin


This security bulletin contains information about 3 vulnerabilities.


EUVDB-ID: #VU77260


Risk: High


CVSSv3.1:


CVE-ID: CVE-2023-33133


CWE-ID: CWE-20 - Improper input validation


Exploit availability: No


Description

The vulnerability allows a remote attacker to execute arbitrary code on the system.


The vulnerability exists due to insufficient validation of user-supplied input in Microsoft Excel. A remote attacker can trick a victim to open a specially crafted file and execute arbitrary code on the target system.


Mitigation

Install updates from vendor's website.


Vulnerable software versions

Microsoft Office: 2019 - 2019 for Mac


Office Online Server : All versions


Microsoft Excel: 2013 - 2016


Microsoft Office LTSC 2021: 32 bit editions - 2021 for Mac


Microsoft 365 Apps for Enterprise: 32-bit Systems - 64-bit Systems


CPE2.3
External links

http://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2023-33133


Q & A


Can this vulnerability be exploited remotely?


How the attacker can exploit this vulnerability?


Is there known malware, which exploits this vulnerability?



EUVDB-ID: #VU77264


Risk: High


CVSSv3.1:


CVE-ID: CVE-2023-33137


CWE-ID: CWE-20 - Improper input validation


Exploit availability: No


Description

The vulnerability allows a remote attacker to execute arbitrary code on the system.


The vulnerability exists due to insufficient validation of user-supplied input in Microsoft Excel. ..

Support the originator by clicking the read the rest link below.