CVE-2022-33632

Description

Microsoft Office Security Feature Bypass Vulnerability

Risk Information

Base Score
4.6
MODERATE
Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C
EPSS Score
Exploitation Probability
0.636

Associated Vulnerability

VulnerabilityOS Platform
Windows Graphics Component Information Disclosure Vulnerability for Office 2019 for x64 1808 of volume version(10388.20027)Windows
Update for Office 2019 for x64 1808 of volume version(10388.20027) For Home EditionWindows
Windows Graphics Component Information Disclosure Vulnerability for Office 2019 for x86 1808 of volume version(10388.20027)Windows
Update for Office 2019 for x86 1808 of volume version(10388.20027) For Home EditionWindows
Windows Graphics Component Information Disclosure Vulnerability for Office 2019 for x86 1808 of version(10388.20027)Windows
Update for Office 2019 for x86 1808 of version(10388.20027) For Home EditionWindows
Windows Graphics Component Information Disclosure Vulnerability for Office 2019 for x64 1808 of version(10388.20027)Windows
Update for Office 2019 for x64 1808 of version(10388.20027) For Home EditionWindows
Windows Graphics Component Information Disclosure Vulnerability for Office 2019 for 1808 of Volume License Version (10388.20027) (Online Installer)Windows
Update for Office 2019 for 1808 of Volume License Version (10388.20027) (Online Installer) For Home EditionWindows
Windows Graphics Component Information Disclosure Vulnerability for Office 2021 for x64 2108 of volume version(14332.20345)Windows
Update for Office 2021 for x64 2108 of volume version(14332.20345) For Home EditionWindows
Windows Graphics Component Information Disclosure Vulnerability for Office 2021 for x86 2108 of volume version(14332.20345)Windows
Update for Office 2021 for x86 2108 of volume version(14332.20345) For Home EditionWindows
Windows Graphics Component Information Disclosure Vulnerability for Microsoft 365 Apps for Business Semi Annual Channel for x64 2202 of version(14931.20604)Windows
Update for Microsoft 365 Apps for Business Semi Annual Channel for x64 2202 of version(14931.20604) For Home EditionWindows
Windows Graphics Component Information Disclosure Vulnerability for Microsoft 365 Apps for Business Semi Annual Channel for x86 2202 of version(14931.20604)Windows
Update for Microsoft 365 Apps for Business Semi Annual Channel for x86 2202 of version(14931.20604) For Home EditionWindows
Windows Graphics Component Information Disclosure Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Channel for x64 2202 of version(14931.20604)Windows
Update for Microsoft 365 Apps for Enterprise Semi Annual Channel for x64 2202 of version(14931.20604) For Home EditionWindows
Windows Graphics Component Information Disclosure Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Channel for x86 2202 of version(14931.20604)Windows
Update for Microsoft 365 Apps for Enterprise Semi Annual Channel for x86 2202 of version(14931.20604) For Home EditionWindows
Windows Graphics Component Information Disclosure Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Preview Channel for x64 2202 of version(14931.20604)Windows
Update for Microsoft 365 Apps for Enterprise Semi Annual Preview Channel for x64 2202 of version(14931.20604) For Home EditionWindows
Windows Graphics Component Information Disclosure Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Preview Channel for x86 2202 of version(14931.20604)Windows
Update for Microsoft 365 Apps for Enterprise Semi Annual Preview Channel for x86 2202 of version(14931.20604) For Home EditionWindows
Windows Graphics Component Information Disclosure Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Channel for x64 2202 of version(14931.20604)Windows
Update for Microsoft 365 Apps for Enterprise Semi Annual Channel for x64 2202 of version(14931.20604) For Home EditionWindows
Windows Graphics Component Information Disclosure Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Channel for x86 2202 of version(14931.20604)Windows
Update for Microsoft 365 Apps for Enterprise Semi Annual Channel for x86 2202 of version(14931.20604) For Home EditionWindows
Windows Graphics Component Information Disclosure Vulnerability for Microsoft 365 Apps for Business Semi Annual Channel for x64 2202 of version(14931.20604)Windows
Update for Microsoft 365 Apps for Business Semi Annual Channel for x64 2202 of version(14931.20604) For Home EditionWindows
Windows Graphics Component Information Disclosure Vulnerability for Microsoft 365 Apps for Business Semi Annual Channel for x86 2202 of version(14931.20604)Windows
Update for Microsoft 365 Apps for Business Semi Annual Channel for x86 2202 of version(14931.20604) For Home EditionWindows
Windows Graphics Component Information Disclosure Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Targeted Channel for x64 2202 of version(14931.20604)Windows
Update for Microsoft 365 Apps for Enterprise Semi Annual Targeted Channel for x64 2202 of version(14931.20604) For Home EditionWindows
Windows Graphics Component Information Disclosure Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Targeted Channel for x86 2202 of version(14931.20604)Windows
Update for Microsoft 365 Apps for Enterprise Semi Annual Targeted Channel for x86 2202 of version(14931.20604) For Home EditionWindows
Windows Graphics Component Information Disclosure Vulnerability for Microsoft 365 Apps for Enterprise Semi-Annual Channel Version 2202 (Build 14931.20604) (Online Installer)Windows
Update for Microsoft 365 Apps for Enterprise Semi-Annual Channel Version 2202 (Build 14931.20604) (Online Installer) For Home EditionWindows
Windows Graphics Component Information Disclosure Vulnerability for Microsoft 365 Apps for Enterprise Targeted Channel Version 2202 (Build 14931.20604) (Online Installer)Windows
Update for Microsoft 365 Apps for Enterprise Targeted Channel Version 2202 (Build 14931.20604) (Online Installer) For Home EditionWindows
Windows Graphics Component Information Disclosure Vulnerability for Microsoft 365 Apps for Monthly Enterprise Channel for x64 2205 of version(15225.20356)Windows
Update for Microsoft 365 Apps for Monthly Enterprise Channel for x64 2205 of version(15225.20356) For Home EditionWindows
Windows Graphics Component Information Disclosure Vulnerability for Microsoft 365 Apps for Monthly Enterprise Channel for x86 version 2205 (15225.20356)Windows
Update for Microsoft 365 Apps for Monthly Enterprise Channel for x86 version 2205 (15225.20356) For Home EditionWindows
Windows Graphics Component Information Disclosure Vulnerability for Microsoft 365 Apps for Business Current Channel for x64 2206 of version(15330.20246)Windows
Update for Microsoft 365 Apps for Business Current Channel for x64 2206 of version(15330.20246) For Home EditionWindows
Windows Graphics Component Information Disclosure Vulnerability for Microsoft 365 Apps for Business Current Channel for x86 2206 of version(15330.20246)Windows
Update for Microsoft 365 Apps for Business Current Channel for x86 2206 of version(15330.20246) For Home EditionWindows
Windows Graphics Component Information Disclosure Vulnerability for Microsoft 365 Apps for Enterprise Current Channel for x64 2206 of version(15330.20246)Windows
Update for Microsoft 365 Apps for Enterprise Current Channel for x64 2206 of version(15330.20246) For Home EditionWindows
Windows Graphics Component Information Disclosure Vulnerability for Microsoft 365 Apps for Enterprise Current Channel for x86 2206 of version(15330.20246)Windows
Update for Microsoft 365 Apps for Enterprise Current Channel for x86 2206 of version(15330.20246) For Home EditionWindows
Windows Graphics Component Information Disclosure Vulnerability for Office 2019 for x64 2206 Retail Version (15330.20246)Windows
Update for Office 2019 for x64 2206 Retail Version (15330.20246) For Home EditionWindows
Windows Graphics Component Information Disclosure Vulnerability for Office 2019 for x86 2206 Retail Version (15330.20246)Windows
Update for Office 2019 for x86 2206 Retail Version (15330.20246) For Home EditionWindows
Windows Graphics Component Information Disclosure Vulnerability for Office 2021 for x64 2206 of Retail Version(15330.20246)Windows
Update for Office 2021 for x64 2206 of Retail Version(15330.20246) For Home EditionWindows
Windows Graphics Component Information Disclosure Vulnerability for Office 2021 for x86 2206 of Retail Version(15330.20246)Windows
Update for Office 2021 for x86 2206 of Retail Version(15330.20246) For Home EditionWindows
Windows Graphics Component Information Disclosure Vulnerability for Microsoft 365 Apps for Enterprise Current Channel for x64 2206 of version(15330.20246)Windows
Update for Microsoft 365 Apps for Enterprise Current Channel for x64 2206 of version(15330.20246) For Home EditionWindows
Windows Graphics Component Information Disclosure Vulnerability for Microsoft 365 Apps for Enterprise Current Channel for x86 2206 of version(15330.20246)Windows
Update for Microsoft 365 Apps for Enterprise Current Channel for x86 2206 of version(15330.20246) For Home EditionWindows
Windows Graphics Component Information Disclosure Vulnerability for Microsoft 365 Apps for Business Current Channel for x64 2206 of version(15330.20246)Windows
Update for Microsoft 365 Apps for Business Current Channel for x64 2206 of version(15330.20246) For Home EditionWindows
Windows Graphics Component Information Disclosure Vulnerability for Microsoft 365 Apps for Business Current Channel for x86 2206 of version(15330.20246)Windows
Update for Microsoft 365 Apps for Business Current Channel for x86 2206 of version(15330.20246) For Home EditionWindows
Windows Graphics Component Information Disclosure Vulnerability for Microsoft 365 Apps for Enterprise and Business Current Channel Version 2206 (Build 15330.20246) (Online Installer)Windows
Update for Microsoft 365 Apps for Enterprise and Business Current Channel Version 2206 (Build 15330.20246) (Online Installer) For Home EditionWindows
Microsoft Office Security Feature Bypass Vulnerability for Microsoft Office 2016 (KB5002112) 64-Bit EditionWindows
Microsoft Office Security Feature Bypass Vulnerability for Microsoft Office 2016 (KB5002112) 32-Bit EditionWindows
Microsoft Office Security Feature Bypass Vulnerability for Microsoft Office 2013 (KB5002121) 64-Bit EditionWindows
Microsoft Office Security Feature Bypass Vulnerability for Microsoft Office 2013 (KB5002121) 32-Bit EditionWindows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-34160Update for Office 2019 for x64 1808 of volume version(10388.20027)
PATCH-34162Update for Office 2019 for x86 1808 of volume version(10388.20027)
PATCH-34184Update for Office 2019 for x86 1808 of version(10388.20027)
PATCH-34186Update for Office 2019 for x64 1808 of version(10388.20027)
PATCH-34202Update for Office 2019 for 1808 of Volume License Version (10388.20027) (Online Installer)
PATCH-34168Update for Office 2021 for x64 2108 of volume version(14332.20345)
PATCH-34170Update for Office 2021 for x86 2108 of volume version(14332.20345)
PATCH-34148Update for Microsoft 365 Apps for Business Semi Annual Channel for x64 2202 of version(14931.20604)
PATCH-34150Update for Microsoft 365 Apps for Business Semi Annual Channel for x86 2202 of version(14931.20604)
PATCH-34152Update for Microsoft 365 Apps for Enterprise Semi Annual Channel for x64 2202 of version(14931.20604)
PATCH-34154Update for Microsoft 365 Apps for Enterprise Semi Annual Channel for x86 2202 of version(14931.20604)
PATCH-34156Update for Microsoft 365 Apps for Enterprise Semi Annual Preview Channel for x64 2202 of version(14931.20604)
PATCH-34158Update for Microsoft 365 Apps for Enterprise Semi Annual Preview Channel for x86 2202 of version(14931.20604)
PATCH-34188Update for Microsoft 365 Apps for Enterprise Semi Annual Channel for x64 2202 of version(14931.20604)
PATCH-34190Update for Microsoft 365 Apps for Enterprise Semi Annual Channel for x86 2202 of version(14931.20604)
PATCH-34192Update for Microsoft 365 Apps for Business Semi Annual Channel for x64 2202 of version(14931.20604)
PATCH-34194Update for Microsoft 365 Apps for Business Semi Annual Channel for x86 2202 of version(14931.20604)
PATCH-34196Update for Microsoft 365 Apps for Enterprise Semi Annual Targeted Channel for x64 2202 of version(14931.20604)
PATCH-34198Update for Microsoft 365 Apps for Enterprise Semi Annual Targeted Channel for x86 2202 of version(14931.20604)
PATCH-34200Update for Microsoft 365 Apps for Enterprise Semi-Annual Channel Version 2202 (Build 14931.20604) (Online Installer)
PATCH-34201Update for Microsoft 365 Apps for Enterprise Targeted Channel Version 2202 (Build 14931.20604) (Online Installer)
PATCH-34144Update for Microsoft 365 Apps for Monthly Enterprise Channel for x64 2205 of version(15225.20356)
PATCH-34146Update for Microsoft 365 Apps for Monthly Enterprise Channel for x86 version 2205 (15225.20356)
PATCH-34136Update for Microsoft 365 Apps for Business Current Channel for x64 2206 of version(15330.20246)
PATCH-34138Update for Microsoft 365 Apps for Business Current Channel for x86 2206 of version(15330.20246)
PATCH-34140Update for Microsoft 365 Apps for Enterprise Current Channel for x64 2206 of version(15330.20246)
PATCH-34142Update for Microsoft 365 Apps for Enterprise Current Channel for x86 2206 of version(15330.20246)
PATCH-34164Update for Office 2019 for x64 2206 Retail Version (15330.20246)
PATCH-34166Update for Office 2019 for x86 2206 Retail Version (15330.20246)
PATCH-34172Update for Office 2021 for x64 2206 of Retail Version(15330.20246)
PATCH-34174Update for Office 2021 for x86 2206 of Retail Version(15330.20246)
PATCH-34176Update for Microsoft 365 Apps for Enterprise Current Channel for x64 2206 of version(15330.20246)
PATCH-34178Update for Microsoft 365 Apps for Enterprise Current Channel for x86 2206 of version(15330.20246)
PATCH-34180Update for Microsoft 365 Apps for Business Current Channel for x64 2206 of version(15330.20246)
PATCH-34182Update for Microsoft 365 Apps for Business Current Channel for x86 2206 of version(15330.20246)
PATCH-34199Update for Microsoft 365 Apps for Enterprise and Business Current Channel Version 2206 (Build 15330.20246) (Online Installer)
PATCH-34129Security Update for Microsoft Office 2016 (KB5002112) 64-Bit Edition
PATCH-34130Security Update for Microsoft Office 2016 (KB5002112) 32-Bit Edition
PATCH-34131Security Update for Microsoft Office 2013 (KB5002121) 64-Bit Edition
PATCH-34132Security Update for Microsoft Office 2013 (KB5002121) 32-Bit Edition

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234