CRITICAL · 9.8

CVE-2023-21716

Microsoft Word Remote Code Execution Vulnerability

Vulnerability Description

Microsoft Word Remote Code Execution Vulnerability

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
MicrosoftOffice2019
MicrosoftOffice Long Term Servicing Channel2021
MicrosoftOffice Online Server2016
MicrosoftOffice Web Apps2013
MicrosoftSharepoint Enterprise Server2013
MicrosoftSharepoint Foundation2013
MicrosoftSharepoint Server-
MicrosoftWord2013

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-21716?

CVE-2023-21716 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Microsoft Word Remote Code Execution Vulnerability

How severe is CVE-2023-21716?

CVE-2023-21716 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2023-21716?

Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Office, Microsoft Office Long Term Servicing Channel, Microsoft Office Online Server, Microsoft Office Web Apps, Microsoft Sharepoint Enterprise Server.