Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2023-23396

Опубликовано: 14 мар. 2023
Источник: msrc
CVSS3: 6.5
EPSS Низкий

Описание

Microsoft Excel Denial of Service Vulnerability

FAQ

How could an attacker exploit this vulnerability?

The attacker could exploit this vulnerability by convincing a victim to open a specially crafted XLSX file which when opened would cause a denial-of-service condition for other processes running on that machine.

Is the Preview Pane an attack vector for this vulnerability?

No, the Preview Pane is not an attack vector.

According to the CVSS metric, the attack vector is network (AV:N). What does that mean for this vulnerability?

An attacker could trigger this vulnerability by convincing a victim to access a malicious file via a network connection or by downloading and opening the malicious file locally. In the worst case scenario, the malicious file could be triggered with a web request (AV:N). When multiple attack vectors can be used, we assign a score based on the scenario with the higher risk.

Обновления

ПродуктСтатьяОбновление
Microsoft Office Web Apps Server 2013 Service Pack 1
Microsoft Office Online Server

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

DOS

N/A

EPSS

Процентиль: 89%
0.04919
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
почти 3 года назад

Microsoft Excel Denial of Service Vulnerability

CVSS3: 6.5
github
почти 3 года назад

Microsoft Excel Denial of Service Vulnerability

CVSS3: 6.5
fstec
почти 3 года назад

Уязвимость пакетов программ Microsoft Office, связанная с некорректной зачисткой или освобождением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 89%
0.04919
Низкий

6.5 Medium

CVSS3