CVE-2022-24462

Description

Microsoft Word Security Feature Bypass Vulnerability

Risk Information

Base Score
5.4
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C
EPSS Score
Exploitation Probability
0.89

Associated Vulnerability

VulnerabilityOS Platform
Microsoft Office Visio Remote Code Execution Vulnerability for Office 2019 for x64 1808 of volume version(10384.20023)Windows
Update for Office 2019 for x64 1808 of volume version(10384.20023) For Home EditionWindows
Microsoft Office Visio Remote Code Execution Vulnerability for Office 2019 for x86 1808 of volume version(10384.20023)Windows
Update for Office 2019 for x86 1808 of volume version(10384.20023) For Home EditionWindows
Microsoft Office Visio Remote Code Execution Vulnerability for Office 2019 for x86 1808 of version(10384.20023)Windows
Update for Office 2019 for x86 1808 of version(10384.20023) For Home EditionWindows
Microsoft Office Visio Remote Code Execution Vulnerability for Office 2019 for x64 1808 of version(10384.20023)Windows
Update for Office 2019 for x64 1808 of version(10384.20023) For Home EditionWindows
Microsoft Office Visio Remote Code Execution Vulnerability for Office 2019 for 1808 of Volume License Version (10384.20023) (Online Installer)Windows
Update for Office 2019 for 1808 of Volume License Version (10384.20023) (Online Installer) For Home EditionWindows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Semi Annual Channel for x64 2108 of version(14326.20852)Windows
Update for Microsoft 365 Apps for Business Semi Annual Channel for x64 2108 of version(14326.20852) For Home EditionWindows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Semi Annual Channel for x86 2108 of version(14326.20852)Windows
Update for Microsoft 365 Apps for Business Semi Annual Channel for x86 2108 of version(14326.20852) For Home EditionWindows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Channel for x64 2108 of version(14326.20852)Windows
Update for Microsoft 365 Apps for Enterprise Semi Annual Channel for x64 2108 of version(14326.20852) For Home EditionWindows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Channel for x86 2108 of version(14326.20852)Windows
Update for Microsoft 365 Apps for Enterprise Semi Annual Channel for x86 2108 of version(14326.20852) For Home EditionWindows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Channel for x64 2108 of version(14326.20852)Windows
Update for Microsoft 365 Apps for Enterprise Semi Annual Channel for x64 2108 of version(14326.20852) For Home EditionWindows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Channel for x86 2108 of version(14326.20852)Windows
Update for Microsoft 365 Apps for Enterprise Semi Annual Channel for x86 2108 of version(14326.20852) For Home EditionWindows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Semi Annual Channel for x64 2108 of version(14326.20852)Windows
Update for Microsoft 365 Apps for Business Semi Annual Channel for x64 2108 of version(14326.20852) For Home EditionWindows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Semi Annual Channel for x86 2108 of version(14326.20852)Windows
Update for Microsoft 365 Apps for Business Semi Annual Channel for x86 2108 of version(14326.20852) For Home EditionWindows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi-Annual Channel Version 2108 (Build 14326.20852) (Online Installer)Windows
Update for Microsoft 365 Apps for Enterprise Semi-Annual Channel Version 2108 (Build 14326.20852) (Online Installer) For Home EditionWindows
Microsoft Office Visio Remote Code Execution Vulnerability for Office 2021 for x64 2108 of volume version(14332.20255)Windows
Microsoft Office Visio Remote Code Execution Vulnerability for Office 2021 for x86 2108 of volume version(14332.20255)Windows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Monthly Enterprise Channel for x64 2201 of version(14827.20220)Windows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Monthly Enterprise Channel for x86 version 2201 (14827.20220)Windows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Current Channel for x64 2202 of version(14931.20132)Windows
Update for Microsoft 365 Apps for Business Current Channel for x64 2202 of version(14931.20132) For Home EditionWindows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Current Channel for x86 2202 of version(14931.20132)Windows
Update for Microsoft 365 Apps for Business Current Channel for x86 2202 of version(14931.20132) For Home EditionWindows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Current Channel for x64 2202 of version(14931.20132)Windows
Update for Microsoft 365 Apps for Enterprise Current Channel for x64 2202 of version(14931.20132) For Home EditionWindows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Current Channel for x86 2202 of version(14931.20132)Windows
Update for Microsoft 365 Apps for Enterprise Current Channel for x86 2202 of version(14931.20132) For Home EditionWindows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Preview Channel for x64 2202 of version(14931.20132)Windows
Update for Microsoft 365 Apps for Enterprise Semi Annual Preview Channel for x64 2202 of version(14931.20132) For Home EditionWindows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Preview Channel for x86 2202 of version(14931.20132)Windows
Update for Microsoft 365 Apps for Enterprise Semi Annual Preview Channel for x86 2202 of version(14931.20132) For Home EditionWindows
Microsoft Office Visio Remote Code Execution Vulnerability for Office 2019 for x64 2202 Retail Version (14931.20132)Windows
Microsoft Office Visio Remote Code Execution Vulnerability for Office 2019 for x86 2202 Retail Version (14931.20132)Windows
Microsoft Office Visio Remote Code Execution Vulnerability for Office 2021 for x64 2202 of Retail Version(14931.20132)Windows
Microsoft Office Visio Remote Code Execution Vulnerability for Office 2021 for x86 2202 of Retail Version(14931.20132)Windows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Current Channel for x64 2202 of version(14931.20132)Windows
Update for Microsoft 365 Apps for Enterprise Current Channel for x64 2202 of version(14931.20132) For Home EditionWindows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Current Channel for x86 2202 of version(14931.20132)Windows
Update for Microsoft 365 Apps for Enterprise Current Channel for x86 2202 of version(14931.20132) For Home EditionWindows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Current Channel for x64 2202 of version(14931.20132)Windows
Update for Microsoft 365 Apps for Business Current Channel for x64 2202 of version(14931.20132) For Home EditionWindows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Current Channel for x86 2202 of version(14931.20132)Windows
Update for Microsoft 365 Apps for Business Current Channel for x86 2202 of version(14931.20132) For Home EditionWindows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Targeted Channel for x64 2202 of version(14931.20132)Windows
Update for Microsoft 365 Apps for Enterprise Semi Annual Targeted Channel for x64 2202 of version(14931.20132) For Home EditionWindows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Targeted Channel for x86 2202 of version(14931.20132)Windows
Update for Microsoft 365 Apps for Enterprise Semi Annual Targeted Channel for x86 2202 of version(14931.20132) For Home EditionWindows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Targeted Channel Version 2202 (Build 14931.20132) (Online Installer)Windows
Update for Microsoft 365 Apps for Enterprise Targeted Channel Version 2202 (Build 14931.20132) (Online Installer) For Home EditionWindows
Microsoft Office Visio Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Current Channel Version 2202 (Build 14931.20132) (Online Installer)Windows
Update for Microsoft 365 Apps for Enterprise Current Channel Version 2202 (Build 14931.20132) (Online Installer) For Home EditionWindows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-33323Update for Office 2019 for x64 1808 of volume version(10384.20023)
PATCH-33325Update for Office 2019 for x86 1808 of volume version(10384.20023)
PATCH-33347Update for Office 2019 for x86 1808 of version(10384.20023)
PATCH-33349Update for Office 2019 for x64 1808 of version(10384.20023)
PATCH-33362Update for Office 2019 for 1808 of Volume License Version (10384.20023) (Online Installer)
PATCH-33311Update for Microsoft 365 Apps for Business Semi Annual Channel for x64 2108 of version(14326.20852)
PATCH-33313Update for Microsoft 365 Apps for Business Semi Annual Channel for x86 2108 of version(14326.20852)
PATCH-33315Update for Microsoft 365 Apps for Enterprise Semi Annual Channel for x64 2108 of version(14326.20852)
PATCH-33317Update for Microsoft 365 Apps for Enterprise Semi Annual Channel for x86 2108 of version(14326.20852)
PATCH-33351Update for Microsoft 365 Apps for Enterprise Semi Annual Channel for x64 2108 of version(14326.20852)
PATCH-33353Update for Microsoft 365 Apps for Enterprise Semi Annual Channel for x86 2108 of version(14326.20852)
PATCH-33355Update for Microsoft 365 Apps for Business Semi Annual Channel for x64 2108 of version(14326.20852)
PATCH-33357Update for Microsoft 365 Apps for Business Semi Annual Channel for x86 2108 of version(14326.20852)
PATCH-33363Update for Microsoft 365 Apps for Enterprise Semi-Annual Channel Version 2108 (Build 14326.20852) (Online Installer)
PATCH-33331Update for Office 2021 for x64 2108 of volume version(14332.20255)
PATCH-33333Update for Office 2021 for x86 2108 of volume version(14332.20255)
PATCH-33307Update for Microsoft 365 Apps for Monthly Enterprise Channel for x64 2201 of version(14827.20220)
PATCH-33309Update for Microsoft 365 Apps for Monthly Enterprise Channel for x86 version 2201 (14827.20220)
PATCH-33299Update for Microsoft 365 Apps for Business Current Channel for x64 2202 of version(14931.20132)
PATCH-33301Update for Microsoft 365 Apps for Business Current Channel for x86 2202 of version(14931.20132)
PATCH-33303Update for Microsoft 365 Apps for Enterprise Current Channel for x64 2202 of version(14931.20132)
PATCH-33305Update for Microsoft 365 Apps for Enterprise Current Channel for x86 2202 of version(14931.20132)
PATCH-33319Update for Microsoft 365 Apps for Enterprise Semi Annual Preview Channel for x64 2202 of version(14931.20132)
PATCH-33321Update for Microsoft 365 Apps for Enterprise Semi Annual Preview Channel for x86 2202 of version(14931.20132)
PATCH-33327Update for Office 2019 for x64 2202 Retail Version (14931.20132)
PATCH-33329Update for Office 2019 for x86 2202 Retail Version (14931.20132)
PATCH-33335Update for Office 2021 for x64 2202 of Retail Version(14931.20132)
PATCH-33337Update for Office 2021 for x86 2202 of Retail Version(14931.20132)
PATCH-33339Update for Microsoft 365 Apps for Enterprise Current Channel for x64 2202 of version(14931.20132)
PATCH-33341Update for Microsoft 365 Apps for Enterprise Current Channel for x86 2202 of version(14931.20132)
PATCH-33343Update for Microsoft 365 Apps for Business Current Channel for x64 2202 of version(14931.20132)
PATCH-33345Update for Microsoft 365 Apps for Business Current Channel for x86 2202 of version(14931.20132)
PATCH-33359Update for Microsoft 365 Apps for Enterprise Semi Annual Targeted Channel for x64 2202 of version(14931.20132)
PATCH-33361Update for Microsoft 365 Apps for Enterprise Semi Annual Targeted Channel for x86 2202 of version(14931.20132)
PATCH-33364Update for Microsoft 365 Apps for Enterprise Targeted Channel Version 2202 (Build 14931.20132) (Online Installer)
PATCH-33365Update for Microsoft 365 Apps for Enterprise Current Channel Version 2202 (Build 14931.20132) (Online Installer)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234