CVE-2023-28285
Severity CVSS v4.0:
Pending analysis
Type:
CWE-416
Use After Free
Publication date:
11/04/2023
Last modified:
01/01/2025
Description
Microsoft Office Remote Code Execution Vulnerability
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:*:* | ||
| cpe:2.3:a:microsoft:office:2019:*:*:*:*:macos:*:* | ||
| cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:macos:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28285
- http://packetstormsecurity.com/files/173127/Microsoft-Office-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/173140/Microsoft-365-MSO-2305-Build-16.0.16501.20074-Remote-Code-Execution.html
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28285



