ZDI-CAN-18976: ZDI-23-1784: Microsoft Word SKP File Parsing Use-After-Free Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft Word. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-18976?
The severity of ZDI-CAN-18976 is classified as high due to the potential for sensitive information disclosure.
How do I fix ZDI-CAN-18976?
To fix ZDI-CAN-18976, ensure that Microsoft Word is updated to the latest version where the vulnerability is addressed.
What types of attacks can occur due to ZDI-CAN-18976?
ZDI-CAN-18976 allows remote attackers to exploit users through malicious pages or files to disclose sensitive information.
Is user interaction required for ZDI-CAN-18976 exploitation?
Yes, user interaction is required for ZDI-CAN-18976 exploitation as the target must visit a malicious page or open a malicious file.
Which versions of Microsoft Word are affected by ZDI-CAN-18976?
ZDI-CAN-18976 affects installations of Microsoft Word, particularly on Android devices.