ZDI-23-1786: Microsoft Word SKP File Parsing Memory Corruption Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Word. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-1786?
The ZDI-23-1786 vulnerability has a CVSS rating that indicates a significant level of risk due to the potential for remote code execution.
How do I fix ZDI-23-1786?
To fix ZDI-23-1786, users should apply the latest security updates provided by Microsoft for Microsoft Word.
Who is affected by ZDI-23-1786?
ZDI-23-1786 affects installations of Microsoft Word, particularly on the Android platform.
What types of attacks are possible with ZDI-23-1786?
ZDI-23-1786 allows remote attackers to execute arbitrary code, requiring user interaction such as visiting a malicious page or opening a harmful file.
Is user interaction necessary for ZDI-23-1786 exploitation?
Yes, user interaction is necessary for exploiting ZDI-23-1786, as the target must actively visit a malicious page or open a compromised document.