CVE-2022-23252

Description

Microsoft Office Information Disclosure Vulnerability

Risk Information

Base Score
5.4
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
EPSS Score
Exploitation Probability
0.344

Associated Vulnerability

VulnerabilityOS Platform
Microsoft Office Information Disclosure Vulnerability for Microsoft Office 2016 (KB3118335) 64-Bit EditionWindows
Microsoft Office Information Disclosure Vulnerability for Microsoft Office 2016 (KB3118335) 32-Bit EditionWindows
Microsoft Office Information Disclosure Vulnerability for Microsoft Office 2013 (KB3172514) 64-Bit EditionWindows
Microsoft Office Information Disclosure Vulnerability for Microsoft Office 2013 (KB3172514) 32-Bit EditionWindows
Microsoft Office Visio Remote Code Execution Vulnerability for Office 2019 for x86 1808 of version(10383.20027)Windows
Microsoft Office Visio Remote Code Execution Vulnerability for Office 2019 for x64 1808 of version(10383.20027)Windows
Microsoft Office Visio Remote Code Execution Vulnerability for Office 2019 for x64 1808 of volume version(10383.20027)Windows
Microsoft Office Visio Remote Code Execution Vulnerability for Office 2019 for x86 1808 of volume version(10383.20027)Windows
Microsoft Office Visio Remote Code Execution Vulnerability for Office 2019 for 1808 of Volume License Version (10383.20027) (Online Installer)Windows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Channel for x64 2108 of version(14326.20784)Windows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Channel for x86 2108 of version(14326.20784)Windows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Semi Annual Channel for x64 2108 of version(14326.20784)Windows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Semi Annual Channel for x86 2108 of version(14326.20784)Windows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Targeted Channel for x64 2108 of version(14326.20784)Windows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Targeted Channel for x86 2108 of version(14326.20784)Windows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi-Annual Channel Version 2108 (Build 14326.20784) (Online Installer)Windows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Targeted Channel Version 2108 (Build 14326.20784) (Online Installer)Windows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Semi Annual Channel for x64 2108 of version(14326.20784)Windows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Semi Annual Channel for x86 2108 of version(14326.20784)Windows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Channel for x64 2108 of version(14326.20784)Windows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Channel for x86 2108 of version(14326.20784)Windows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Preview Channel for x64 2108 of version(14326.20784)Windows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Preview Channel for x86 2108 of version(14326.20784)Windows
Microsoft Office Visio Remote Code Execution Vulnerability for Office 2021 for x64 2108 of volume version(14332.20238)Windows
Microsoft Office Visio Remote Code Execution Vulnerability for Office 2021 for x86 2108 of volume version(14332.20238)Windows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Monthly Enterprise Channel for x64 2112 of version(14729.20322)Windows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Monthly Enterprise Channel for x86 version 2112 (14729.20322)Windows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Current Channel for x64 2201 of version(14827.20192)Windows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Current Channel for x86 2201 of version(14827.20192)Windows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Current Channel for x64 2201 of version(14827.20192)Windows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Current Channel for x86 2201 of version(14827.20192)Windows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Current Channel Version 2201 (Build 14827.20192) (Online Installer)Windows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Current Channel for x64 2201 of version(14827.20192)Windows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Current Channel for x86 2201 of version(14827.20192)Windows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Current Channel for x64 2201 of version(14827.20192)Windows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Current Channel for x86 2201 of version(14827.20192)Windows
Microsoft Office Visio Remote Code Execution Vulnerability for Office 2019 for x64 2201 Retail Version (14827.20192)Windows
Microsoft Office Visio Remote Code Execution Vulnerability for Office 2019 for x86 2201 Retail Version (14827.20192)Windows
Microsoft Office Visio Remote Code Execution Vulnerability for Office 2021 for x64 2201 of Retail Version(14827.20192)Windows
Microsoft Office Visio Remote Code Execution Vulnerability for Office 2021 for x86 2201 of Retail Version(14827.20192)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-33116Security Update for Microsoft Office 2016 (KB3118335) 64-Bit Edition
PATCH-33117Security Update for Microsoft Office 2016 (KB3118335) 32-Bit Edition
PATCH-33143Update for Office 2019 for x86 1808 of version(10383.20027)
PATCH-33145Update for Office 2019 for x64 1808 of version(10383.20027)
PATCH-33186Update for Office 2019 for x64 1808 of volume version(10383.20027)
PATCH-33188Update for Office 2019 for x86 1808 of volume version(10383.20027)
PATCH-33201Update for Office 2019 for 1808 of Volume License Version (10383.20027) (Online Installer)
PATCH-33147Update for Microsoft 365 Apps for Enterprise Semi Annual Channel for x64 2108 of version(14326.20784)
PATCH-33149Update for Microsoft 365 Apps for Enterprise Semi Annual Channel for x86 2108 of version(14326.20784)
PATCH-33151Update for Microsoft 365 Apps for Business Semi Annual Channel for x64 2108 of version(14326.20784)
PATCH-33153Update for Microsoft 365 Apps for Business Semi Annual Channel for x86 2108 of version(14326.20784)
PATCH-33155Update for Microsoft 365 Apps for Enterprise Semi Annual Targeted Channel for x64 2108 of version(14326.20784)
PATCH-33157Update for Microsoft 365 Apps for Enterprise Semi Annual Targeted Channel for x86 2108 of version(14326.20784)
PATCH-33158Update for Microsoft 365 Apps for Enterprise Semi-Annual Channel Version 2108 (Build 14326.20784) (Online Installer)
PATCH-33159Update for Microsoft 365 Apps for Enterprise Targeted Channel Version 2108 (Build 14326.20784) (Online Installer)
PATCH-33174Update for Microsoft 365 Apps for Business Semi Annual Channel for x64 2108 of version(14326.20784)
PATCH-33176Update for Microsoft 365 Apps for Business Semi Annual Channel for x86 2108 of version(14326.20784)
PATCH-33178Update for Microsoft 365 Apps for Enterprise Semi Annual Channel for x64 2108 of version(14326.20784)
PATCH-33180Update for Microsoft 365 Apps for Enterprise Semi Annual Channel for x86 2108 of version(14326.20784)
PATCH-33182Update for Microsoft 365 Apps for Enterprise Semi Annual Preview Channel for x64 2108 of version(14326.20784)
PATCH-33184Update for Microsoft 365 Apps for Enterprise Semi Annual Preview Channel for x86 2108 of version(14326.20784)
PATCH-33194Update for Office 2021 for x64 2108 of volume version(14332.20238)
PATCH-33196Update for Office 2021 for x86 2108 of volume version(14332.20238)
PATCH-33170Update for Microsoft 365 Apps for Monthly Enterprise Channel for x64 2112 of version(14729.20322)
PATCH-33172Update for Microsoft 365 Apps for Monthly Enterprise Channel for x86 version 2112 (14729.20322)
PATCH-33135Update for Microsoft 365 Apps for Enterprise Current Channel for x64 2201 of version(14827.20192)
PATCH-33137Update for Microsoft 365 Apps for Enterprise Current Channel for x86 2201 of version(14827.20192)
PATCH-33139Update for Microsoft 365 Apps for Business Current Channel for x64 2201 of version(14827.20192)
PATCH-33141Update for Microsoft 365 Apps for Business Current Channel for x86 2201 of version(14827.20192)
PATCH-33160Update for Microsoft 365 Apps for Enterprise Current Channel Version 2201 (Build 14827.20192) (Online Installer)
PATCH-33162Update for Microsoft 365 Apps for Business Current Channel for x64 2201 of version(14827.20192)
PATCH-33164Update for Microsoft 365 Apps for Business Current Channel for x86 2201 of version(14827.20192)
PATCH-33166Update for Microsoft 365 Apps for Enterprise Current Channel for x64 2201 of version(14827.20192)
PATCH-33168Update for Microsoft 365 Apps for Enterprise Current Channel for x86 2201 of version(14827.20192)
PATCH-33190Update for Office 2019 for x64 2201 Retail Version (14827.20192)
PATCH-33192Update for Office 2019 for x86 2201 Retail Version (14827.20192)
PATCH-33198Update for Office 2021 for x64 2201 of Retail Version(14827.20192)
PATCH-33200Update for Office 2021 for x86 2201 of Retail Version(14827.20192)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234