First published: Wed Dec 18 2024(Updated: )
A library injection vulnerability exists in Microsoft Excel 16.83 for macOS. A specially crafted library can leverage Excel's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this vulnerability and then make use of the vulnerable application's permissions.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Excel for Mac |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-43106 is classified as a critical vulnerability due to its potential for permission bypass.
To mitigate CVE-2024-43106, ensure that you install the latest updates for Microsoft Excel on macOS.
CVE-2024-43106 specifically affects Microsoft Excel 16.83 for macOS.
CVE-2024-43106 can be exploited by a malicious application that injects a specially crafted library into Microsoft Excel.
Yes, user action is needed to run the malicious application that exploits CVE-2024-43106.