ZDI-CAN-20358: ZDI-23-1789: Microsoft Excel SKP File Parsing Uninitialized Variable Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft Excel. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2023-33146.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-20358?
The severity of ZDI-CAN-20358 is assessed as moderate due to the requirement for user interaction to exploit the vulnerability.
How do I fix ZDI-CAN-20358?
To fix ZDI-CAN-20358, ensure that you have the latest security updates installed for Microsoft Excel.
What are the potential impacts of ZDI-CAN-20358?
ZDI-CAN-20358 can lead to the disclosure of sensitive information if a user interacts with a malicious page or opens a malicious file.
Who is affected by ZDI-CAN-20358?
Users of Microsoft Excel on affected installations are vulnerable to ZDI-CAN-20358.
Is user interaction necessary for ZDI-CAN-20358?
Yes, user interaction is necessary for ZDI-CAN-20358, as the target must visit a malicious page or open a harmful file.