← back
CVE-2023-21716criticalobserved exploitationCWE-190

Microsoft Word Remote Code Execution Vulnerability

94Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.

ssvc Actcvss 9.8epss 82%
from disclosure to weapon21 days
Published on NVDFeb 14
1st PoC+21d
VulnCheck+401d
exploitation probability
82%top 1% of all CVEs
observed exploitation
yesVulnCheck
21 public exploit(s)
In short

A critical vulnerability in Microsoft Word allows an attacker to execute arbitrary code on a victim's computer by tricking them into opening a specially crafted document. This can lead to complete system compromise without requiring any special user permissions.

Technical detail

An integer overflow vulnerability (CWE-190) in Microsoft Word's document parsing engine allows remote code execution when processing maliciously crafted Word files. The attack vector is document opening via email or web download; no user interaction beyond opening the file is required, enabling unauthenticated RCE with CVSS 9.8 severity.

Summary generated and translated by AI from the official description.
Microsoft Word Remote Code Execution Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.