ZDI-23-1768: Microsoft Word SKP File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Word. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-1768?
ZDI-23-1768 has been assigned a high severity rating due to the potential for remote code execution.
How does ZDI-23-1768 allow exploitation?
ZDI-23-1768 requires user interaction, as the target must open a malicious file or visit a harmful web page.
Which software is affected by ZDI-23-1768?
ZDI-23-1768 affects Microsoft Word installations, notably Microsoft Word for Android.
How can I mitigate the risks associated with ZDI-23-1768?
To mitigate the risks of ZDI-23-1768, ensure that your Microsoft Word software is updated to the latest version.
Are there any known attack vectors for ZDI-23-1768?
The primary attack vectors for ZDI-23-1768 include malicious links and infected files shared through email or online platforms.