CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
AI Score
Confidence
High
EPSS
Percentile
95.7%
Multiple vulnerabilities were found in Microsoft Office. Malicious users can exploit these vulnerabilities to execute arbitrary code, spoof user interface.
Below is a complete list of vulnerabilities:
CVE-2023-28311 critical
CVE-2023-28288 critical
CVE-2023-28285 critical
CVE-2023-28287 critical
CVE-2023-28295 critical
Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update component usually can be accessed from the Control Panel) and updates from the Update Options section, that are listed in your Office Account (Office Account tab usually can be accessed from the File menu)
Arbitrary code execution. Exploitation of vulnerabilities with this impact can lead to executing by abuser any code or commands at vulnerable machine or process.
Spoof user interface. Exploitation of vulnerabilities with this impact can lead to changes in user interface to beguile user into inaccurate behavior.
support.microsoft.com/kb/5002213
support.microsoft.com/kb/5002221
support.microsoft.com/kb/5002373
support.microsoft.com/kb/5002375
support.microsoft.com/kb/5002381
support.microsoft.com/kb/5002383
support.microsoft.com/kb/5002385
msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28285
msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28287
msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28288
msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28295
msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28311
statistics.securelist.com/
threats.kaspersky.com/en/product/Microsoft-Office/
threats.kaspersky.com/en/product/Microsoft-SharePoint/