CVE-2023-35371: Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.76.23081101 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10401.20022Patch KB5002435
Event History
Frequently Asked Questions
What is CVE-2023-35371?
CVE-2023-35371 is a Microsoft Office Remote Code Execution Vulnerability.
What is the severity of CVE-2023-35371?
The severity of CVE-2023-35371 is high (CVSS score: 7.8).
Which software is affected by CVE-2023-35371?
Microsoft Office 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office LTSC 2021, and Microsoft Office Online Server are affected by CVE-2023-35371.
How do I fix CVE-2023-35371?
To fix CVE-2023-35371, apply the security updates provided by Microsoft. Links to the updates can be found in the Microsoft Office updates documentation.
Where can I find more information about CVE-2023-35371?
You can find more information about CVE-2023-35371 on the Microsoft Security Response Center website.