CVE-2022-41106
published 2022-11-09CVE-2022-41106: Microsoft Excel Remote Code Execution Vulnerability
PriorityP357high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
2.24%
80.9th percentile
Microsoft Excel Remote Code Execution Vulnerability
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | excel | — | — |
| microsoft | excel | — | — |
| microsoft | microsoft_365_apps_for_enterprise | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_excel_2013_service_pack_1 | >= 15.0.0.0 < 15.0.5501.1000 | 15.0.5501.1000 |
| microsoft | microsoft_excel_2016 | >= 16.0.0.0 < 16.0.5369.1000 | 16.0.5369.1000 |
| microsoft | microsoft_office_2019 | >= 19.0.0 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_ltsc_2021 | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_online_server | >= 16.0.1 < 16.0.10392.20000 | 16.0.10392.20000 |
| microsoft | microsoft_office_web_apps_server_2013_service_pack_1 | >= 15.0.1 < 15.0.5501.1000 | 15.0.5501.1000 |
| microsoft | office | — | — |
| microsoft | office_long_term_servicing_channel | — | — |
| microsoft | office_web_apps_server | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_32-bit_systems | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_64-bit_systems | — | — |
| msrc | microsoft_excel_2013_rt_service_pack_1 | — | — |
| msrc | microsoft_excel_2013_service_pack_1 | — | — |
| msrc | microsoft_excel_2016 | — | — |
| msrc | microsoft_office_2019_for_32-bit_editions | — | — |
| msrc | microsoft_office_2019_for_64-bit_editions | — | — |
| msrc | microsoft_office_ltsc_2021_for_32-bit_editions | — | — |
| msrc | microsoft_office_ltsc_2021_for_64-bit_editions | — | — |
| msrc | microsoft_office_online_server | — | — |
| msrc | microsoft_office_web_apps_server_2013_service_pack_1 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
snort↗
60500-60501
- →Exploitation requires a victim to open a specially crafted (malicious) file delivered via social engineering; monitor for suspicious Excel file opens from untrusted/downloaded sources. ↗
- →The Preview Pane is NOT an attack vector; exploitation requires the file to be fully opened by the user. ↗
- →Attack is carried out locally after user interaction (file open); correlate local process execution anomalies following Excel file open events. ↗
- ·Snort rules 60500-60501 are subject to change as additional vulnerability information becomes available; always reference the latest rules from Firepower Management Center or Snort.org. ↗
- ·Confirmed vulnerable versions are Microsoft Office Excel 2019 x86 version 2207 build 15427.20210 and version 2202 build 14931.20660; scope detection/patching efforts accordingly. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Microsoft Excel up to Office Online Server Remote Code Execution
vuldb·2026-05-19·CVSS 8.8
CVE-2022-41106 [HIGH] Microsoft Excel up to Office Online Server Remote Code Execution
A vulnerability, which was classified as critical, was found in Microsoft Excel up to Office Online Server. Impacted is an unknown function. Such manipulation leads to Remote Code Execution.
This vulnerability is uniquely identified as CVE-2022-41106. The attack can be launched remotely. No exploit exists.
Applying a patch is advised to resolve this issue.
GHSA
GHSA-7fp7-jf54-c7g3: Microsoft Excel Remote Code Execution Vulnerability
ghsa_unreviewed·2022-11-10·CVSS 7.8
CVE-2022-41106 [HIGH] GHSA-7fp7-jf54-c7g3: Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-41063.
GHSA
GHSA-g4ch-vmqj-9j84: Microsoft Excel Remote Code Execution Vulnerability
ghsa_unreviewed·2022-11-10·CVSS 8.8
CVE-2022-41063 [HIGH] GHSA-g4ch-vmqj-9j84: Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-41106.
Microsoft
Microsoft Excel Remote Code Execution Vulnerability
vendor_msrc·2022-11-08·CVSS 8.8
CVE-2022-41106 [HIGH] Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
FAQ: Is the Preview Pane an attack vector for this vulnerability?
No, the Preview Pane is not an attack vector.
FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?
The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally.
For example, when the score indicates that the Attack Vector is Local and User Interaction is Required, this could describe an exploit in which an attacker, through social engineering, convinces a victim to download and open a specially crafted file from a website which leads to a local attack on thei
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Microsoft Office class attribute double-free vulnerability
blogs_talos·2022-11-15·CVSS 8.8
[HIGH] Vulnerability Spotlight: Microsoft Office class attribute double-free vulnerability
## Vulnerability Spotlight: Microsoft Office class attribute double-free vulnerability
Cisco Talos recently discovered a class attribute double-free vulnerability in Microsoft Office.
Microsoft Office is a suite of tools used for productivity in both a corporate environment as well as by end-users. It offers a range of tools that can be used for various purposes. Such as Excel for spreadsheets, Word for document editing, Outlook for email, PowerPoint for presentations, etc.
Talos has identified a double-free vulnerability in Microsoft Office Excel. TALOS-2022-1591 (CVE-2022-41106) allows an attacker to provide a malicious file to trigger a possible arbitrary code execution.
Cisco Talos worked with Microsoft to ensure that this issue was resolved and an update is available for affected
Talos
Vulnerability Spotlight: Microsoft Office class attribute double-free vulnerability
blogs_talos·2022-11-15·CVSS 8.8
CVE-2022-4110 [HIGH] Vulnerability Spotlight: Microsoft Office class attribute double-free vulnerability
Cisco Talos recently discovered a class attribute double-free vulnerability in Microsoft Office.
Microsoft Office is a suite of tools used for productivity in both a corporate environment as well as by end-users. It offers a range of tools that can be used for various purposes. Such as Excel for spreadsheets, Word for document editing, Outlook for email, PowerPoint for presentations, etc.
Talos has identified a double-free vulnerability in Microsoft Office Excel. TALOS-2022-1591 (CVE-2022-41106) allows an attacker to provide a malicious file to trigger a possible arbitrary code execution.
Cisco Talos worked with Microsoft to ensure that this issue was resolved and an update is available for affected customers, all in adherence to Cisco’s vulnerability disclosure policy.
Users are encou
Talos
Microsoft Patch Tuesday for November 2022 — Snort rules and prominent vulnerabilities
blogs_talos·2022-11-08·CVSS 8.1
CVE-2022-41039 [HIGH] Microsoft Patch Tuesday for November 2022 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for November 2022 — Snort rules and prominent vulnerabilities
Microsoft released its monthly security update on Tuesday, disclosing 62 vulnerabilities. Of these vulnerabilities, 8 are classified as “Critical” and the rest are classified as “Important.”
Three of the critical entries are remote code execution (RCE) vulnerabilities for Windows Point-to-Point Tunneling Protocol (PPTP).
CVE-2022-41039
CVE-2022-41044
CVE-2022-41088
An unauthenticated attacker can send a specially crafted request to an RAS (Remote Access Server), which may lead to remote code execution. Although according to Microsoft, these three vulnerabilities are less likely to be exploited, as the attacker must win a complex race condition. In August of 2022’s Patch Tuesday release, several v
Talos
Microsoft Patch Tuesday for November 2022 — Snort rules and prominent vulnerabilities
blogs_talos·2022-11-08·CVSS 8.1
CVE-2022-41039 [HIGH] Microsoft Patch Tuesday for November 2022 — Snort rules and prominent vulnerabilities
Microsoft released its monthly security update on Tuesday, disclosing 62 vulnerabilities. Of these vulnerabilities, 8 are classified as “Critical” and the rest are classified as “Important.”
Three of the critical entries are remote code execution (RCE) vulnerabilities for Windows Point-to-Point Tunneling Protocol (PPTP).
- CVE-2022-41039
- CVE-2022-41044
- CVE-2022-41088
An unauthenticated attacker can send a specially crafted request to an RAS (Remote Access Server), which may lead to remote code execution. Although according to Microsoft, these three vulnerabilities are less likely to be exploited, as the attacker must win a complex race condition. In August of 2022’s Patch Tuesday release, several vulnerabilities for Windows PPTP were also disclosed.
Another notable vulnerability in
2022-11-09
Published