CVE-2023-21715: Microsoft Publisher Security Feature Bypass Vulnerability
Microsoft Office Publisher contains a security feature bypass vulnerability that allows for a local, authenticated attack on a targeted system.
Other sources
Microsoft Publisher Security Feature Bypass Vulnerability
— NVD
Microsoft Publisher Security Features Bypass Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases
Event History
Frequently Asked Questions
What is CVE-2023-21715?
CVE-2023-21715 is a security feature bypass vulnerability in Microsoft Office Publisher.
How severe is CVE-2023-21715?
CVE-2023-21715 has a severity value of 7, which is considered high.
Which software products are affected by CVE-2023-21715?
Microsoft Office Publisher, Microsoft Office 365 Apps for Enterprise (x86 and x86_64) are affected by CVE-2023-21715.
How can I fix CVE-2023-21715?
To fix CVE-2023-21715, update Microsoft Office Publisher and Microsoft Office 365 Apps for Enterprise to the latest security updates.
Where can I find more information about CVE-2023-21715?
You can find more information about CVE-2023-21715 on the Microsoft Security Response Center website.