CVE-2023-36897: Visual Studio Tools for Office Runtime Spoofing Vulnerability
Visual Studio Tools for Office Runtime Spoofing Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.4.10 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.2.18 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.9.56 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.6.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.60910Patch KB5029497 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.11.29
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-36897.
What is the severity of CVE-2023-36897?
CVE-2023-36897 has a severity rating of 8.1 (high).
Which software products are affected by CVE-2023-36897?
The following software products are affected by CVE-2023-36897: Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office LTSC 2021, Microsoft Visual Studio 2017, Microsoft Visual Studio 2019, and Microsoft Visual Studio 2022.
How can I fix CVE-2023-36897?
To fix CVE-2023-36897, you should apply the relevant security updates provided by Microsoft for the affected software products.
Where can I find more information about CVE-2023-36897?
You can find more information about CVE-2023-36897 on the Microsoft Security Response Center (MSRC) website.