ZDI-23-385: Microsoft Office Word SKP File Parsing Use-After-Free Remote Code Execution Vulnerability
Published Apr 11, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Office Word. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
1 affected component
Microsoft Office Word
Event History
Apr 11, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-385?
The severity of ZDI-23-385 is rated at 61, indicating a moderate risk level.
2
How do I fix ZDI-23-385?
To fix ZDI-23-385, ensure that Microsoft Office Word is updated to the latest version where this vulnerability has been addressed.
3
What type of vulnerability is ZDI-23-385?
ZDI-23-385 is a Use-After-Free vulnerability that allows remote code execution in Microsoft Office Word.
4
What conditions are necessary to exploit ZDI-23-385?
Exploitation of ZDI-23-385 requires user interaction, such as opening a malicious file or visiting a malicious page.
5
Which software is affected by ZDI-23-385?
ZDI-23-385 affects installations of Microsoft Office Word.