vendor:
Word
by:
nu11secur1ty
7.5
CVSS
HIGH
Remote Code Execution (RCE)
284
CWE
Product Name: Word
Affected Version From: 16.72.23040900
Affected Version To: 16.72.23040900
Patch Exists: YES
Related CWE: CVE-2023-28311
CPE: a:microsoft:word:16.72.23040900
Platforms Tested:
2023
Microsoft Word 16.72.23040900 – Remote Code Execution (RCE)
The attack itself is carried out locally by a user with authentication to the targeted system. An attacker could exploit the vulnerability by convincing a victim, through social engineering, to download and open a specially crafted file from a website which could lead to a local attack on the victim's computer. The attacker can trick the victim to open a malicious web page by using a `Word` malicious file and he can steal credentials, bank accounts information, sniffing and tracking all the traffic of the victim without stopping - it depends on the scenario and etc.
Mitigation:
The mitigation for this vulnerability is to ensure that all users are aware of the risks of downloading and opening files from untrusted sources. Additionally, users should be trained to recognize and avoid social engineering attacks.