ZDI-23-1421: Microsoft Office Word FBX File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Office Word. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2023-27909.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-1421?
ZDI-23-1421 has a high severity rating due to its potential for remote code execution.
How do I fix ZDI-23-1421?
To fix ZDI-23-1421, ensure that your Microsoft Office Word is updated to the latest security patch provided by Microsoft.
Who is affected by ZDI-23-1421?
ZDI-23-1421 affects installations of Microsoft Office Word that have not been patched against this vulnerability.
What type of attack does ZDI-23-1421 involve?
ZDI-23-1421 involves remote code execution attacks requiring user interaction to exploit.
What products are vulnerable to ZDI-23-1421?
The vulnerable product for ZDI-23-1421 is Microsoft Office Word.