Severity
8.8HIGH
EPSS
39.3%
top 2.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 9
Latest updateDec 19

Description

A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory, aka 'Microsoft Office Remote Code Execution Vulnerability'.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages4 packages

Patches

🔴Vulnerability Details

49
GHSA
FurqanSoftware/node-whois vulnerable to Prototype Pollution2022-12-19
GHSA
hoek subject to prototype pollution via the clone function.2022-09-25
GHSA
js-ini Prorotype Pollution when malicious INI files submitted to an application that parses it with `parse`2022-07-26
GHSA
ion-parser Prototype Pollution when malicious INI file submitted to application that parses with `parse`2022-07-26
GHSA
Prototype Pollution in deep-get-set2022-06-25

📋Vendor Advisories

3
Red Hat
hapi/hoek: Prototype Pollution in @hapi/hoek2022-09-23
Microsoft
All versions of package datatables.net are vulnerable to Prototype Pollution2020-12-08
Microsoft
Microsoft Office Remote Code Execution Vulnerability2020-06-09