ZDI-24-1075: Microsoft PowerShell Reference for Office Products officedocs-cdn Uncontrolled Search Path Element Remote Code Execution Vulnerability
Published Aug 5, 2024
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft PowerShell Reference for Office Products. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8.
Affected Software
1 affected component
Microsoft PowerShell Reference for Office Products
Event History
Aug 5, 2024
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-24-1075?
The ZDI-24-1075 vulnerability has a CVSS rating of 9.8, indicating a critical severity level.
2
What types of installations are affected by ZDI-24-1075?
ZDI-24-1075 affects installations of Microsoft PowerShell Reference for Office Products.
3
Can ZDI-24-1075 be exploited without authentication?
Yes, ZDI-24-1075 can be exploited by remote attackers without the need for authentication.
4
What impact does ZDI-24-1075 have on systems?
ZDI-24-1075 allows remote attackers to execute arbitrary code on affected systems.
5
How should organizations address the ZDI-24-1075 vulnerability?
Organizations should apply the relevant security patches or updates provided by Microsoft for ZDI-24-1075.