ZDI-23-1784: Microsoft Word SKP File Parsing Use-After-Free Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft Word. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-1784?
The severity of ZDI-23-1784 has been classified with a CVSS score, indicating a significant risk to data confidentiality due to information disclosure.
How do I fix ZDI-23-1784?
To fix ZDI-23-1784, ensure that your Microsoft Word installation is updated to the latest version to patch the vulnerability.
What types of sensitive information can be disclosed by ZDI-23-1784?
ZDI-23-1784 allows remote attackers to potentially disclose sensitive data, which may include user documents and other confidential information.
Is user interaction required to exploit ZDI-23-1784?
Yes, user interaction is required to exploit ZDI-23-1784, as the target must either visit a malicious page or open a malicious file.
Which software versions are affected by ZDI-23-1784?
ZDI-23-1784 affects installations of Microsoft Word, particularly those used on Android devices.