目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1000 CNY

100.0%

CVE-2023-21716— Microsoft Word 安全漏洞

CVSS 9.8 · Critical EPSS 91.42% · P100
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2023-21716の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
Microsoft Word Remote Code Execution Vulnerability
ソース: NVD (National Vulnerability Database)
脆弱性説明
Microsoft Word Remote Code Execution Vulnerability
ソース: NVD (National Vulnerability Database)
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ソース: NVD (National Vulnerability Database)
脆弱性タイプ
整数溢出或超界折返
ソース: NVD (National Vulnerability Database)
脆弱性タイトル
Microsoft Word 安全漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Microsoft Word是美国微软(Microsoft)公司的一套Office套件中的文字处理软件。 Microsoft Office Word存在安全漏洞。以下产品和版本受到影响:Microsoft Office Online Server,Microsoft Office 2019 for Mac,Microsoft 365 Apps for Enterprise for 64-bit Systems,Microsoft SharePoint Enterprise Server 2016,Micr
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

Shenlong 10 Questions — AI 深度分析

十问解析:根本原因、利用方式、修复建议、紧迫性。摘要免费,完整版需登录。

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
MicrosoftMicrosoft Office LTSC for Mac 2021 16.0.1 ~ 16.70.23021201 -
MicrosoftMicrosoft Office LTSC 2021 16.0.1 ~ https://aka.ms/OfficeSecurityReleases -
MicrosoftMicrosoft SharePoint Server Subscription Edition 16.0.0 ~ 16.0.15601.20478 -
MicrosoftMicrosoft 365 Apps for Enterprise 16.0.1 ~ https://aka.ms/OfficeSecurityReleases -
MicrosoftSharePoint Server Subscription Edition Language Pack 16.0.0 ~ 16.0.15601.20478 -
MicrosoftMicrosoft Office Online Server 16.0.1 ~ 16.0.10395.20001 -
MicrosoftMicrosoft Office 2019 for Mac 16.0.0 ~ 16.70.23021201 -
MicrosoftMicrosoft Office 2019 19.0.0 ~ https://aka.ms/OfficeSecurityReleases -
MicrosoftMicrosoft SharePoint Enterprise Server 2016 16.0.0 ~ 16.0.5383.1000 -
MicrosoftMicrosoft SharePoint Enterprise Server 2013 Service Pack 1 15.0.0 ~ 15.0.5529.1000 -
MicrosoftMicrosoft SharePoint Server 2019 16.0.0 ~ 16.0.10395.20001 -
MicrosoftMicrosoft Word 2016 16.0.1 ~ 16.0.5383.1000 -
MicrosoftMicrosoft Office Web Apps Server 2013 Service Pack 1 15.0.1 ~ 15.0.5529.1000 -
MicrosoftMicrosoft SharePoint Foundation 2013 Service Pack 1 15.0.0 ~ 15.0.5529.1000 -
MicrosoftMicrosoft Word 2013 Service Pack 1 15.0.1 ~ 15.0.5529.1000 -
MicrosoftMicrosoft Word 2013 Service Pack 1 15.0.1 ~ 15.0.5529.1000 -

II. CVE-2023-21716の公開POC

#POC説明ソースリンクShenlongリンク
1Nonehttps://github.com/FeatherStark/CVE-2023-21716POC詳細
2RTF Crash POC Python 3.11 Windows 10https://github.com/Xnuvers007/CVE-2023-21716POC詳細
3A vulnerability within Microsoft Office's wwlib allows attackers to achieve remote code execution with the privileges of the victim that opens a malicious RTF document. The attacker could deliver this file as an email attachment (or other means).https://github.com/gyaansastra/CVE-2023-21716POC詳細
4Results of retrohunt for files matching YARA rules from https://github.com/AmgdGocha/Detection-Rules/blob/main/CVE-2023-21716.yarhttps://github.com/mikesxrs/CVE-2023-21716_YARA_ResultsPOC詳細
5Microsoft Word 远程代码执行漏洞https://github.com/CKevens/CVE-2023-21716-POCPOC詳細
6test of exploit for CVE-2023-21716https://github.com/hv0l/CVE-2023-21716_exploitPOC詳細
7POC : CVE-2023-21716 Microsoft Word RTF Font Table Heap Corruptionhttps://github.com/JMousqueton/CVE-2023-21716POC詳細
8python program to exploit CVE-2023-21716https://github.com/Lord-of-the-IoT/CVE-2023-21716POC詳細
9This is an exploit file which is used to check CVE-2021-21716 vulnerabilityhttps://github.com/MojithaR/CVE-2023-21716-EXPLOIT.pyPOC詳細
10Microsoft Word 远程代码执行漏洞https://github.com/3yujw7njai/CVE-2023-21716-POCPOC詳細
11POC CVE 2023-21716https://github.com/n0s3ns33/poc-cve-2023-21716POC詳細
12Proof Of Concept for CVE-2023-21716 Microsoft Word Heap Corruptionhttps://github.com/RonF98/CVE-2023-21716-POCPOC詳細
13Microsoft Word 远程代码执行漏洞https://github.com/AiK1d/CVE-2023-21716-POCPOC詳細
14Nonehttps://github.com/Threekiii/Awesome-POC/blob/master/%E5%85%B6%E4%BB%96%E6%BC%8F%E6%B4%9E/Microsoft%20Word%20%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E%20CVE-2023-21716.mdPOC詳細
15Microsoft Word 远程代码执行漏洞https://github.com/P4x1s/CVE-2023-21716-POCPOC詳細
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2023-21716のインテリジェンス情報

登录查看更多情报信息。

Same Patch Batch · Microsoft · 2023-02-14 · 78 CVEs total

CVE-2023-216899.8 CRITICALMicrosoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulner
CVE-2023-216909.8 CRITICALMicrosoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulner
CVE-2023-216929.8 CRITICALMicrosoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulner
CVE-2023-218039.8 CRITICALWindows iSCSI Discovery Service Remote Code Execution Vulnerability
CVE-2023-216858.8 HIGHMicrosoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
CVE-2023-216848.8 HIGHMicrosoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
CVE-2023-217068.8 HIGHMicrosoft Exchange Server Remote Code Execution Vulnerability
CVE-2023-217058.8 HIGHMicrosoft SQL Server Remote Code Execution Vulnerability
CVE-2023-217078.8 HIGHMicrosoft Exchange Server Remote Code Execution Vulnerability
CVE-2023-217178.8 HIGHMicrosoft SharePoint Server Elevation of Privilege Vulnerability
CVE-2023-215298.8 HIGHMicrosoft Exchange Server Remote Code Execution Vulnerability
CVE-2023-217138.8 HIGHMicrosoft SQL Server Remote Code Execution Vulnerability
CVE-2023-217988.8 HIGHMicrosoft ODBC Driver Remote Code Execution Vulnerability
CVE-2023-217998.8 HIGHMicrosoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
CVE-2023-216868.8 HIGHMicrosoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
CVE-2023-217978.8 HIGHMicrosoft ODBC Driver Remote Code Execution Vulnerability
CVE-2023-217778.7 HIGHAzure App Service on Azure Stack Hub Elevation of Privilege Vulnerability
CVE-2023-233748.3 HIGHMicrosoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2023-218068.2 HIGHPower BI Report Server Spoofing Vulnerability
CVE-2023-217788.0 HIGHMicrosoft Dynamics Unified Service Desk Remote Code Execution Vulnerability

Showing 20 of 78 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2023-21716へのコメント

まだコメントはありません


コメントを残す