ZDI-CAN-19625: ZDI-23-1768: Microsoft Word SKP File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Word. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-19625?
ZDI-CAN-19625 has been assigned a significant severity due to its ability to allow remote code execution.
How do I fix ZDI-CAN-19625?
To mitigate ZDI-CAN-19625, ensure Microsoft Word is updated to the latest version that includes security patches addressing this vulnerability.
What software is affected by ZDI-CAN-19625?
ZDI-CAN-19625 specifically affects Microsoft Word for Android.
Is user interaction required to exploit ZDI-CAN-19625?
Yes, user interaction is required as the target must open a malicious file or visit a malicious web page.
What type of vulnerability is ZDI-CAN-19625?
ZDI-CAN-19625 is classified as a remote code execution vulnerability.