vendor:
Microsoft Office 365
by:
nu11secur1ty
7.5
CVSS
HIGH
Elevation of Privilege
CWE
Product Name: Microsoft Office 365
Affected Version From: 18.2305.1222.0
Affected Version To: 18.2305.1222.0
Patch Exists: NO
Related CWE: CVE-2023-33148
CPE:
Platforms Tested:
2023
Microsoft Office 365 Version 18.2305.1222.0 – Elevation of Privilege + RCE
The Microsoft Office 365 Version 18.2305.1222.0 app is vulnerable to Elevation of Privilege. The attacker can use this vulnerability to attach a very malicious WORD file in the Outlook app which is a part of Microsoft Office 365 and easily can trick the victim to click on it - opening it and executing a very dangerous shell command, in the background of the local PC. This execution is without downloading this malicious file, and this is a potential problem and a very dangerous case! This can be the end of the victim's PC, it depends on the scenario.