CVE-2023-33137: Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5400.1000Patch KB5002405 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10399.20000Patch KB5002401 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.5563.1000Patch KB5002414
Event History
Frequently Asked Questions
What is CVE-2023-33137?
CVE-2023-33137 is a remote code execution vulnerability in Microsoft Excel.
How severe is CVE-2023-33137?
CVE-2023-33137 has a severity rating of 7.8 (high).
Which software versions are affected by CVE-2023-33137?
CVE-2023-33137 affects Microsoft Office 2019 (64-bit editions), Excel 2013 RT (SP1), Office 2019 (32-bit editions), Excel 2016 (64-bit), Excel 2013 (32-bit, SP1), Excel 2016 (32-bit), Excel 2013 (64-bit, SP1), and Office Online Server.
How can I fix CVE-2023-33137?
To fix CVE-2023-33137, apply the relevant security updates provided by Microsoft for the affected software versions.
Where can I find more information about CVE-2023-33137?
You can find more information about CVE-2023-33137 on the Microsoft Security Response Center website.