ZDI-CAN-21615: ZDI-23-1421: Microsoft Office Word FBX File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Office Word. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2023-27909.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-21615?
The severity of ZDI-CAN-21615 is critical due to the potential for remote code execution.
How do I fix ZDI-CAN-21615?
To fix ZDI-CAN-21615, ensure that you apply the latest security updates for Microsoft Office Word.
What versions of Microsoft Office Word are affected by ZDI-CAN-21615?
ZDI-CAN-21615 affects all supported versions of Microsoft Office Word.
What type of attack vector is leveraged in ZDI-CAN-21615?
ZDI-CAN-21615 is exploited via user interaction, requiring the target to open a malicious file or visit a malicious webpage.
What are the potential impacts of ZDI-CAN-21615?
The potential impacts of ZDI-CAN-21615 include unauthorized access and execution of arbitrary code on the affected system.