Executive brief
Microsoft Word contains an information disclosure vulnerability due to improper input validation. An attacker can exploit this to disclose sensitive information, and the vulnerability has been observed being exploited in the wild.
Affected products
- Microsoft Word 2013 Service Pack 1
- Microsoft Word 2016
- Microsoft Office 2019
- Microsoft Office LTSC 2021
- Microsoft Microsoft 365 Apps for Enterprise
Timeline
- 2023-09-12: disclosed
- 2023-09-12: patched
- 2023-09-12: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-09-12: exploited: Reported as exploited in the wild at time of publication.