U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2023-36884

Change History

CVE Modified by Microsoft Corporation 8/08/2023 2:15:15 PM

Action Type Old Value New Value
Added CVSS V3.1

								
							
							
						
Microsoft Corporation AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Removed CVSS V3.1
Microsoft Corporation AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

								
						
Changed Description
Microsoft is investigating reports of a series of remote code execution vulnerabilities impacting Windows and Office products. Microsoft is aware of targeted attacks that attempt to exploit these vulnerabilities by using specially-crafted Microsoft Office documents.

An attacker could create a specially crafted Microsoft Office document that enables them to perform remote code execution in the context of the victim. However, an attacker would have to convince the victim to open the malicious file.

Upon completion of this investigation, Microsoft will take the appropriate action to help protect our customers. This might include providing a security update through our monthly release process or providing an out-of-cycle security update, depending on customer needs.

Please see the Microsoft Threat Intelligence  Blog Entry https://aka.ms/Storm-0978  for important information about steps you can take to protect your system from this vulnerability.

This CVE will be updated with new information and links to security updates when they become available. If you wish to be notified when these updates are released, we recommend that you register for the security notifications mailer to be alerted of content changes to this CVE. See  Microsoft Technical Security Notifications https://www.microsoft.com/en-us/msrc/technical-security-notifications .

Windows Search Security Feature Bypass Vulnerability