CVE-2023-33152: Microsoft ActiveX Remote Code Execution Vulnerability
Microsoft ActiveX Remote Code Execution Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.5571.1000Patch KB5002069 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5404.1000Patch KB5002058 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases
Event History
Frequently Asked Questions
What is the severity of CVE-2023-33152?
The severity of CVE-2023-33152 is high with a severity value of 7.
Which software versions are affected by CVE-2023-33152?
Office 2019 for 32-bit editions, Office 2019 for 64-bit editions, Office LTSC 2021 for 32-bit editions, Office LTSC 2021 for 64-bit editions, 365 Apps for Enterprise (x86 and x86_64 variants), Office 2013 (64-bit with SP1, and 32-bit with SP1), Office 2016 (32-bit and 64-bit), and Office 2013 RT (with SP1) are affected by CVE-2023-33152.
How can I fix CVE-2023-33152?
To fix CVE-2023-33152, apply the security updates provided by Microsoft for the affected software versions. Visit the Microsoft website for more information and download the necessary patches.
Where can I find more information about CVE-2023-33152?
You can find more information about CVE-2023-33152 on the Microsoft Security Response Center (MSRC) website.
What is the Common Weakness Enumeration (CWE) for CVE-2023-33152?
The Common Weakness Enumeration (CWE) for CVE-2023-33152 is NVD-CWE-noinfo.