First published: Tue Jul 11 2023(Updated: )
Microsoft ActiveX Remote Code Execution Vulnerability
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office 2013 | ||
Microsoft Office 2013 | ||
Microsoft Office 2016 | ||
Microsoft Office 2016 | ||
Microsoft Office 2013 RT | ||
Microsoft 365 Apps | ||
Microsoft 365 Apps | ||
Microsoft Office | =2013-sp1 | |
Microsoft Office | =2013-sp1 | |
Microsoft Office | =2013-sp1 | |
Microsoft Office | =2016 | |
Microsoft Office | =2016 | |
Microsoft Office | =2019 | |
Microsoft Office | =2019 | |
Microsoft Office | =2021 | |
Microsoft Office | =2021 | |
Microsoft Office LTSC 2021 for 64-bit editions | ||
Microsoft Office 2019 for 32-bit editions | ||
Microsoft Office 2019 for 64-bit editions | ||
Microsoft Office LTSC 2021 for 32-bit editions | ||
Microsoft 365 Apps for Enterprise | ||
Microsoft 365 Apps for Enterprise |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-33152 is high with a severity value of 7.
Office 2019 for 32-bit editions, Office 2019 for 64-bit editions, Office LTSC 2021 for 32-bit editions, Office LTSC 2021 for 64-bit editions, 365 Apps for Enterprise (x86 and x86_64 variants), Office 2013 (64-bit with SP1, and 32-bit with SP1), Office 2016 (32-bit and 64-bit), and Office 2013 RT (with SP1) are affected by CVE-2023-33152.
To fix CVE-2023-33152, apply the security updates provided by Microsoft for the affected software versions. Visit the Microsoft website for more information and download the necessary patches.
You can find more information about CVE-2023-33152 on the Microsoft Security Response Center (MSRC) website.
The Common Weakness Enumeration (CWE) for CVE-2023-33152 is NVD-CWE-noinfo.