ZDI-CAN-23296: ZDI-24-1075: Microsoft PowerShell Reference for Office Products officedocs-cdn Uncontrolled Search Path Element Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft PowerShell Reference for Office Products. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-23296?
The severity of ZDI-CAN-23296 is rated at 9.8 on the CVSS scale, indicating a critical vulnerability.
How do I fix ZDI-CAN-23296?
To fix ZDI-CAN-23296, ensure that your installation of Microsoft PowerShell Reference for Office Products is updated to the latest version provided by Microsoft.
Who can exploit ZDI-CAN-23296?
ZDI-CAN-23296 can be exploited by remote attackers without the need for authentication.
What types of attacks can be executed using ZDI-CAN-23296?
ZDI-CAN-23296 allows remote attackers to execute arbitrary code on affected installations.
Which products are affected by ZDI-CAN-23296?
ZDI-CAN-23296 specifically affects Microsoft PowerShell Reference for Office Products.