vendor:
Microsoft 365 MSO
by:
nu11secur1ty
7.5
CVSS
HIGH
Remote Code Execution (RCE)
CWE
Product Name: Microsoft 365 MSO
Affected Version From: Version 2305 Build 16.0.16501.20074
Affected Version To:
Patch Exists: NO
Related CWE: CVE-2023-33137
CPE:
Platforms Tested:
2023
Microsoft 365 MSO (Version 2305 Build 16.0.16501.20074) 32-bit – Remote Code Execution (RCE)
This exploit is connected with third part exploit server, which waits for the victim to call him and execute the content from him using the pipe posting method. When the victim hits the button in the Excel file, it makes a POST request to the exploit server, and the server creates another hidden malicious file and executes it directly on the victim's machine. This is a dangerous 0-day exploit.
Mitigation:
Unknown