ZDI-CAN-21843: ZDI-23-1638: Microsoft Office Word FBX File Parsing Memory Corruption Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Office Word. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2023-36045.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-21843?
The ZDI-CAN-21843 vulnerability is considered to have a high severity due to its potential for remote code execution.
How do I fix ZDI-CAN-21843?
To fix ZDI-CAN-21843, ensure that you apply the latest security updates provided by Microsoft for Office Word.
What type of attack vector does ZDI-CAN-21843 use?
ZDI-CAN-21843 can be exploited through malicious files or websites that require user interaction.
What are the affected versions for ZDI-CAN-21843?
ZDI-CAN-21843 affects installations of Microsoft Office Word, although specific version details may vary.
What should I do if I suspect exploitation of ZDI-CAN-21843?
If you suspect exploitation, disconnect the affected system from the network and consult a cybersecurity professional for further analysis.