Executive brief
Microsoft Office Publisher contains a security feature bypass vulnerability that allows a local, authenticated attacker to bypass security restrictions. The vulnerability requires user interaction and can lead to a high impact on confidentiality, integrity, and availability.
Affected products
- Microsoft Publisher
- Microsoft 365 Apps for Enterprise
Timeline
- 2023-02-14: disclosed
- 2023-02-14: patched
- 2023-02-14: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-02-14: exploited: Reported as exploited in the wild at time of publication.