Rewterz
Rewterz Threat Advisory – Multiple Microsoft Exchange Server Vulnerabilities
September 13, 2023
Rewterz
Rewterz Threat Advisory – Multiple Microsoft Windows Vulnerabilities
September 13, 2023

Advisory Threat Advisory – Multiple Microsoft Office Vulnerabilities

Severity

Medium

Analysis Summary

CVE-2023-41764 CVSS:5.5

Microsoft Office could allow a remote attacker to conduct spoofing attacks.

CVE-2023-36765 CVSS:7.8

Microsoft Office could allow a local authenticated attacker to gain elevated privileges on the system. By executing a specially crafted program, an authenticated attacker could exploit this vulnerability to obtain SYSTEM privileges.

CVE-2023-36767 CVSS:4.3

Microsoft Office could allow a remote attacker to bypass security restrictions. By persuading a victim to open specially crafted content, an attacker could exploit this vulnerability to bypass security features to cause an impact on availability.

Impact

  • Privilege Escalation
  • Gain Access
  • Security Bypass

Indicators Of Compromise

CVE

  • CVE-2023-41764
  • CVE-2023-36765
  • CVE-2023-36767

Affected Vendors

Microsoft

Affected Products

  • Microsoft Office 2013 SP1 x32
  • Microsoft Office 2013 SP1 x64
  • Microsoft Office 2013 SP1 RT
  • Microsoft Office 2016 x32
  • Microsoft Office 2016 x64
  • Microsoft Office 2019 x32
  • Microsoft Office 2019 x64
  • Microsoft 365 Apps for Enterprise x32
  • Microsoft 365 Apps for Enterprise x64
  • Microsoft Office LTSC 2021 x32
  • Microsoft Office LTSC 2021 x64

Remediation

Use Microsoft Automatic Update to apply the appropriate patch for your system, or the Microsoft Security Update Guide to search for available patches.

CVE-2023-41764

CVE-2023-36765

CVE-2023-36767