Junglewise Threat Intelligence

CVE-2023-36761: Microsoft Word Information Disclosure Vulnerability

CVE-2023-36761 · Severity: critical · CVSS 6.5 · Exploited in the wild · Published 2023-09-12

Technologies: Microsoft Word 2016, Microsoft Office LTSC 2021, Microsoft 365 Apps for Enterprise, Microsoft Office 2019. Vendors: Microsoft.

Executive brief

Microsoft Word contains an information disclosure vulnerability due to improper input validation. An attacker can exploit this to disclose sensitive information, and the vulnerability has been observed being exploited in the wild.

Affected products

  • Microsoft Word 2013 Service Pack 1
  • Microsoft Word 2016
  • Microsoft Office 2019
  • Microsoft Office LTSC 2021
  • Microsoft Microsoft 365 Apps for Enterprise

Timeline

  • 2023-09-12: disclosed
  • 2023-09-12: patched
  • 2023-09-12: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-09-12: exploited: Reported as exploited in the wild at time of publication.

Related threats