Junglewise Threat Intelligence

CVE-2023-21715: Microsoft Office Publisher Security Feature Bypass Vulnerability

CVE-2023-21715 · Severity: critical · CVSS 7.3 · Exploited in the wild · Published 2023-02-14

Technologies: Microsoft Office, Microsoft 365 Apps for Enterprise. Vendors: Microsoft.

Executive brief

Microsoft Office Publisher contains a security feature bypass vulnerability that allows a local, authenticated attacker to bypass security restrictions. The vulnerability requires user interaction and can lead to a high impact on confidentiality, integrity, and availability.

Affected products

  • Microsoft Publisher
  • Microsoft 365 Apps for Enterprise

Timeline

  • 2023-02-14: disclosed
  • 2023-02-14: patched
  • 2023-02-14: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-02-14: exploited: Reported as exploited in the wild at time of publication.

Related threats