Lucene search

K
mscveMicrosoftMS:CVE-2024-20673
HistoryFeb 13, 2024 - 8:00 a.m.

Microsoft Office Remote Code Execution Vulnerability

2024-02-1308:00:00
Microsoft
msrc.microsoft.com
51
microsoft
office
remote code execution
vulnerability

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

7.3

Confidence

Low

EPSS

0.001

Percentile

19.5%

Affected configurations

Vulners
Node
microsoftskype_for_businessRange<16.0.5435.1000
OR
microsoftskype_for_businessRange<16.0.5435.1000
OR
microsoftpublisherRange<16.0.5435.1000
OR
microsoftpublisherRange<16.0.5435.1000
OR
microsoftwordRange<16.0.5435.1000
OR
microsoftwordRange<16.0.5435.1000
OR
microsoftvisioRange<16.0.5435.1000
OR
microsoftvisioRange<16.0.5435.1000
OR
microsoftpowerpointRange<16.0.5435.1000
OR
microsoftpowerpointRange<16.0.5435.1000
OR
microsoftofficeRange<16.0.5435.1001
OR
microsoftofficeRange<16.0.5435.1001
OR
microsoftofficeRange<16.0.5435.1001
OR
microsoftofficeRange<16.0.5435.1001
OR
microsoftofficeRange<16.0.5435.1001
OR
microsoftofficeRange<16.0.5435.1001
OR
microsoftofficeRange<16.0.5435.1001
OR
microsoftofficeRange<16.0.5435.1001
OR
microsoftexcelRange<16.0.5435.1000
OR
microsoftexcelRange<16.0.5435.1000
OR
microsoftoffice_long_term_servicing_channelRange<https://aka.ms/OfficeSecurityReleases
OR
microsoftoffice_long_term_servicing_channelRange<https://aka.ms/OfficeSecurityReleases
OR
microsoftofficeRange<https://aka.ms/OfficeSecurityReleases
OR
microsoftofficeRange<https://aka.ms/OfficeSecurityReleases
VendorProductVersionCPE
microsoftskype_for_business*cpe:2.3:a:microsoft:skype_for_business:*:*:*:*:*:*:*:*
microsoftpublisher*cpe:2.3:a:microsoft:publisher:*:*:*:*:*:*:*:*
microsoftword*cpe:2.3:a:microsoft:word:*:*:*:*:*:*:*:*
microsoftvisio*cpe:2.3:a:microsoft:visio:*:*:*:*:*:*:*:*
microsoftpowerpoint*cpe:2.3:a:microsoft:powerpoint:*:*:*:*:*:*:*:*
microsoftoffice*cpe:2.3:a:microsoft:office:*:*:*:*:*:*:*:*
microsoftexcel*cpe:2.3:a:microsoft:excel:*:*:*:*:*:*:*:*
microsoftoffice_long_term_servicing_channel*cpe:2.3:a:microsoft:office_long_term_servicing_channel:*:*:*:*:*:*:*:*

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

7.3

Confidence

Low

EPSS

0.001

Percentile

19.5%