CVE-2023-33140: Microsoft OneNote Spoofing Vulnerability
Published Jun 13, 2023
·Updated
Microsoft OneNote Spoofing Vulnerability
Affected Software
2 affected componentsFixes available
Microsoft OneNote
Microsoft OneNote for Universal<16.0.14326.21450
16.0.14326.21450
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.14326.21450
Event History
Jun 13, 2023
CVE Published
07:00 AM
Data Sourced
07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
Description
CVE Published
via MITRE·11:26 PM
Data Sourced
via MITRE·11:26 PM
DescriptionSeverity
Jun 14, 2023
Data Sourced
via NVD·12:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-33140?
CVE-2023-33140 is a spoofing vulnerability in Microsoft OneNote that allows an attacker to trick a user into viewing manipulated content that appears legitimate.
2
How severe is CVE-2023-33140?
CVE-2023-33140 has a severity score of 6.5, which is considered high.
3
What software is affected by CVE-2023-33140?
Microsoft OneNote and Microsoft OneNote for Universal are affected by CVE-2023-33140.
4
How can I fix CVE-2023-33140?
To fix CVE-2023-33140, ensure that you have the latest updates for Microsoft OneNote and Microsoft OneNote for Universal installed.
5
Where can I find more information about CVE-2023-33140?
You can find more information about CVE-2023-33140 on the Microsoft Security Response Center website.