CVE-2023-21716
published 2023-02-14CVE-2023-21716: Microsoft Word Remote Code Execution Vulnerability
PriorityP189critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
82.30%
99.6th percentile
Microsoft Word Remote Code Execution Vulnerability
Affected
39 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_365_apps_for_enterprise | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_2019 | >= 19.0.0 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_2019_for_mac | >= 16.0.0 < 16.70.23021201 | 16.70.23021201 |
| microsoft | microsoft_office_ltsc_2021 | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_ltsc_for_mac_2021 | >= 16.0.1 < 16.70.23021201 | 16.70.23021201 |
| microsoft | microsoft_office_online_server | >= 16.0.1 < 16.0.10395.20001 | 16.0.10395.20001 |
| microsoft | microsoft_office_web_apps_server_2013_service_pack_1 | >= 15.0.1 < 15.0.5529.1000 | 15.0.5529.1000 |
| microsoft | microsoft_sharepoint_enterprise_server_2013_service_pack_1 | >= 15.0.0 < 15.0.5529.1000 | 15.0.5529.1000 |
| microsoft | microsoft_sharepoint_enterprise_server_2016 | >= 16.0.0 < 16.0.5383.1000 | 16.0.5383.1000 |
| microsoft | microsoft_sharepoint_foundation_2013_service_pack_1 | >= 15.0.0 < 15.0.5529.1000 | 15.0.5529.1000 |
| microsoft | microsoft_sharepoint_server_2019 | >= 16.0.0 < 16.0.10395.20001 | 16.0.10395.20001 |
| microsoft | microsoft_sharepoint_server_subscription_edition | >= 16.0.0 < 16.0.15601.20478 | 16.0.15601.20478 |
| microsoft | microsoft_word_2013_service_pack_1 | >= 15.0.1 < 15.0.5529.1000 | 15.0.5529.1000 |
| microsoft | microsoft_word_2016 | >= 16.0.1 < 16.0.5383.1000 | 16.0.5383.1000 |
| microsoft | office | — | — |
| microsoft | office_long_term_servicing_channel | — | — |
| microsoft | office_online_server | — | — |
| microsoft | office_web_apps | — | — |
| microsoft | sharepoint_enterprise_server | — | — |
| microsoft | sharepoint_enterprise_server | — | — |
| microsoft | sharepoint_foundation | — | — |
| microsoft | sharepoint_server | — | — |
| microsoft | sharepoint_server_subscription_edition_language_pack | >= 16.0.0 < 16.0.15601.20478 | 16.0.15601.20478 |
| microsoft | word | — | — |
| msrc | microsoft_365_apps | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability is triggered by RTF files containing an abnormally large font table definition; detect RTF files with unusually large \fonttbl entries delivered via email or web. ↗
- →The Preview Pane in Outlook is an attack vector — exploitation can occur without the user opening or downloading the attachment; monitor Outlook preview pane rendering of RTF content. ↗
- →Delivery vector is a malicious RTF file sent as an email attachment; alert on inbound emails carrying .rtf attachments, especially from external/untrusted senders. ↗
- →Monitor registry keys HKCU\Software\Microsoft\Office\15.0\Word\Security\FileBlock and HKCU\Software\Microsoft\Office\16.0\Word\Security\FileBlock for RtfFiles DWORD value; absence of value=2 indicates the RTF file-block mitigation is not applied. ↗
- ·Configuring Outlook to read email in plain text removes pictures, specialized fonts, animations, and other rich content, and may cause unexpected behavior in custom code solutions that rely on the object model. ↗
- ·SharePoint Enterprise Server 2013 SP1 customers should install either the cumulative update (ubersrv13) OR both security updates (sts2013 AND loc2013), not necessarily all listed updates. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
vendor_msrc9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-64mm-8wcm-jw5g: Microsoft Word Remote Code Execution Vulnerability
ghsa_unreviewed·2023-02-14
CVE-2023-21716 [CRITICAL] GHSA-64mm-8wcm-jw5g: Microsoft Word Remote Code Execution Vulnerability
Microsoft Word Remote Code Execution Vulnerability
VulnCheck
Microsoft Word Remote Code Execution
vulncheck·2023·CVSS 9.8
CVE-2023-21716 [CRITICAL] Microsoft Word Remote Code Execution
Microsoft Word Remote Code Execution
Microsoft Word Remote Code Execution Vulnerability
Affected: Microsoft Office
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://go.recordedfuture.com/hubfs/reports/ta-2024-0321.pdf
Exploit PoC: https://vulncheck.com/xdb/cafd7b8d1161; https://vulncheck.com/xdb/590c4d4415d4; https://vulncheck.com/xdb/7dd71096a2df; https://vulncheck.com/xdb/a26bd52d812b; https://vulncheck.com/xdb/010f8a0a6112
Microsoft
Microsoft Word Remote Code Execution Vulnerability
vendor_msrc·2023-02-14·CVSS 9.8
CVE-2023-21716 [CRITICAL] CWE-190 Microsoft Word Remote Code Execution Vulnerability
Microsoft Word Remote Code Execution Vulnerability
FAQ: What is the attack vector for this vulnerability?
An unauthenticated attacker could send a malicious e-mail containing an RTF payload that would allow them to gain access to execute commands within the application used to open the malicious file.
FAQ: Is the Preview Pane an attack vector for this vulnerability?
Yes, the Preview Pane is an attack vector.
FAQ: I am running SharePoint Enterprise Server 2013 Service Pack 1. Do I need to install all the updates that are listed for SharePoint Enterprise Server 2013 Service Pack 1?
No. Customers running SharePoint Enterprise Server 2013 Service Pack 1 should install either of the following:
Cumulative update (ubersrv13). Note that this update also includes the *srvloc2013 update
Both of
No detection rules found.
No public exploits indexed.
Greynoiseio
GreyNoise Detects Active Exploitation of CVEs Mentioned in Black Basta’s Leaked Chat Logs
blogs_greynoiseio·2025-02-26·CVSS 9.8
[CRITICAL] GreyNoise Detects Active Exploitation of CVEs Mentioned in Black Basta’s Leaked Chat Logs
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Qualys
Defense Lessons From the Black Basta Ransomware Playbook
blogs_qualys·2025-02-25
Defense Lessons From the Black Basta Ransomware Playbook
## Table of Contents
Know Your Enemys Playbook
Attackers Move Fast
How Qualys Can Help
The cybersecurity world was rocked last week by a massive leak of Black Basta’s internal communications that emerged from the group’s chat logs. Triggered by internal conflicts and a retaliatory data dump following attacks on Russian banks, the exposed records offer a rare glimpse into Black Basta’s tactics, operations, and leadership.
We’ve analyzed these newly unveiled tactics, and in this blog, we equip security teams with clear, actionable insights. We aim to highlight the key lessons learned—like immediate patching, tighter access controls, and rapid incident response—and provide an urgent call to action. This practical guide aims to help organizations strengthen their defenses against evolving
Qualys
Defense Lessons From the Black Basta Ransomware Playbook | Qualys
blogs_qualys·2025-02-25
Defense Lessons From the Black Basta Ransomware Playbook | Qualys
#### Table of Contents
- Know Your Enemys Playbook
- Attackers Move Fast
- How Qualys Can Help
The cybersecurity world was rocked last week by a massive leak of Black Basta’s internal communications that emerged from the group’s chat logs. Triggered by internal conflicts and a retaliatory data dump following attacks on Russian banks, the exposed records offer a rare glimpse into Black Basta’s tactics, operations, and leadership.
We’ve analyzed these newly unveiled tactics, and in this blog, we equip security teams with clear, actionable insights. We aim to highlight the key lessons learned—like immediate patching, tighter access controls, and rapid incident response—and provide an urgent call to action. This practical guide aims to help organizations strengthen their defenses against ev
Sentinelone
CVE-2023-21716 - Microsoft Word Remote Code Execution Vulnerability
blogs_sentinelone·2023-03-09·CVSS 9.8
CVE-2023-21716 [CRITICAL] CVE-2023-21716 - Microsoft Word Remote Code Execution Vulnerability
Microsoft Word is a popular word-processing program used by millions of people worldwide. Unfortunately, it is also a popular target for attackers due to its wide usage.
Recently, a vulnerability has been discovered in Microsoft Word that allows attackers to execute arbitrary code on a victim’s computer.
## Details of the CVE-2023-21716 vulnerability
The vulnerability in Microsoft Word exists in the way that the program parses RTF (Rich Text Format) files. Specifically, the program fails to handle font table definitions larger than a certain size properly. This can lead to a buffer overflow condition, which an attacker can then exploit to execute arbitrary code on the victim’s computer.
### Impact of CVE-2023-21716
The Impact of this vulnerability is through a specially crafted RTF fi
Sentinelone
CVE-2023-21716 - Microsoft Word Remote Code Execution Vulnerability
blogs_sentinelone·2023-03-09·CVSS 9.8
CVE-2023-21716 [CRITICAL] CVE-2023-21716 - Microsoft Word Remote Code Execution Vulnerability
Microsoft Word is a popular word-processing program used by millions of people worldwide. Unfortunately, it is also a popular target for attackers due to its wide usage.
Recently, a vulnerability has been discovered in Microsoft Word that allows attackers to execute arbitrary code on a victim’s computer.
## Details of the CVE-2023-21716 vulnerability
The vulnerability in Microsoft Word exists in the way that the program parses RTF (Rich Text Format) files. Specifically, the program fails to handle font table definitions larger than a certain size properly. This can lead to a buffer overflow condition, which an attacker can then exploit to execute arbitrary code on the victim’s computer.
## Impact of CVE-2023-21716
The Impact of this vulnerability is through a specially crafted RTF fil
Sentinelone
CVE-2023-21839: Oracle WebLogic Server Core Patch Advisory
blogs_sentinelone·2023-03-03·CVSS 7.5
CVE-2023-21839 [HIGH] CVE-2023-21839: Oracle WebLogic Server Core Patch Advisory
Recently, a vulnerability was discovered in Oracle WebLogic Server that can lead to remote code execution. This vulnerability, assigned with CVE-2023-21839, allows an attacker to gain unauthorized access to critical data and take over the vulnerable system.
This vulnerability affects supported versions 12.2.1.3.0, 12.2.1.4.0, and 14.1.1.0.0 and is easily exploitable by an unauthenticated attacker with network access through T3 or IIOP.
This vulnerability is already being exploited in the wild, making it imperative that organizations take immediate action to protect their systems.
## About the CVE-2023-21839 vulnerability
CVE-2023-21839 is an information disclosure vulnerability that can be exploited for remote code execution. This vulnerability is present in Oracle WebLogic Server vers
Qualys
The February 2023 Patch Tuesday Security Update Review
blogs_qualys·2023-02-15
The February 2023 Patch Tuesday Security Update Review
## Table of Contents
Microsoft Patches for February2023
Adobe Patches for February2023
Notable and Critical Microsoft Vulnerabilities Patched
Other Microsoft Vulnerability Highlights
Microsoft Release Summary
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Rapid Response with Patch Management (PM)
EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
Qualys Monthly Webinar Series
This Month in Vulnerabilities & Patches
Microsoft and Adobe have released several monthly security fixes and updates for their products. Let’s take a look at the highlights of this month’s Patch Tuesday as we review and discuss the security updates.
## Microsoft Patches for February 2023
Microsoft has patched 79 vulnerabilities this month, in
Qualys
The February 2023 Patch Tuesday Security Update Review | Qualys
blogs_qualys·2023-02-15
The February 2023 Patch Tuesday Security Update Review | Qualys
#### Table of Contents
- Microsoft Patches for February2023
- Adobe Patches for February2023
- Notable and Critical Microsoft Vulnerabilities Patched
- Other Microsoft Vulnerability Highlights
- Microsoft Release Summary
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- Rapid Response with Patch Management (PM)
- EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
- Qualys Monthly Webinar Series
- This Month in Vulnerabilities & Patches
Microsoft and Adobe have released several monthly security fixes and updates for their products. Let’s take a look at the highlights of this month’s Patch Tuesday as we review and discuss the security updates.
## Microsoft Patches for February 2023
Microsoft has patched 79 vulnerabilities t
Talos
Microsoft Patch Tuesday for February 2023 — Snort rules and prominent vulnerabilities
blogs_talos·2023-02-14·CVSS 9.8
CVE-2023-21823 [CRITICAL] Microsoft Patch Tuesday for February 2023 — Snort rules and prominent vulnerabilities
Microsoft released its monthly security update on Tuesday, disclosing 73 vulnerabilities. Of these vulnerabilities, 8 are classified as “Critical”, 64 are classified as “Important”, one vulnerability is classified as “Moderate.”
According to Microsoft none of the vulnerabilities has been publicly disclosed before Patch Tuesday and only three vulnerabilities were seen in the wild. The most serious one is CVE-2023-21823 a Windows Graphics Component Remote Code Execution Vulnerability. Followed by CVE-2023-21715 a Microsoft Publisher Security Features Bypass Vulnerability which we are describing below and CVE-2023-23376 a local Windows Common Log File System Driver Elevation of Privilege Vulnerability.
Three of the most “Critical“ vulnerabilities, which Microsoft considers to be “more likel
Tenable
Microsoft’s February 2023 Patch Tuesday Addresses 75 CVEs (CVE-2023-23376)
blogs_tenable·2023-02-14·CVSS 7.8
[HIGH] Microsoft’s February 2023 Patch Tuesday Addresses 75 CVEs (CVE-2023-23376)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Krebs
Microsoft Patch Tuesday, February 2023 Edition
blogs_krebs·2023-02-14·CVSS 7.3
CVE-2023-23376 [HIGH] Microsoft Patch Tuesday, February 2023 Edition
Microsoft is sending the world a whole bunch of love today, in the form of patches to plug dozens of security holes in its Windows operating systems and other software. This year’s special Valentine’s Day Patch Tuesday includes fixes for a whopping three different “zero-day” vulnerabilities that are already being used in active attacks.
Microsoft’s security advisories are somewhat sparse with details about the zero-day bugs. Redmond flags CVE-2023-23376 as an “Important” elevation of privilege vulnerability in the Windows Common Log File System Driver , which is present in Windows 10 and 11 systems, as well as many server versions of Windows.
“Sadly, there’s just a little solid information about this privilege escalation,” said Dustin Childs , head of threat awareness at Trend Micro’s Ze
Talos
Microsoft Patch Tuesday for February 2023 — Snort rules and prominent vulnerabilities
blogs_talos·2023-02-14·CVSS 9.8
[CRITICAL] Microsoft Patch Tuesday for February 2023 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for February 2023 — Snort rules and prominent vulnerabilities
Microsoft released its monthly security update on Tuesday, disclosing 73 vulnerabilities. Of these vulnerabilities, 8 are classified as “Critical”, 64 are classified as “Important”, one vulnerability is classified as “Moderate.”
According to Microsoft none of the vulnerabilities has been publicly disclosed before Patch Tuesday and only three vulnerabilities were seen in the wild. The most serious one is CVE-2023-21823 a Windows Graphics Component Remote Code Execution Vulnerability. Followed by CVE-2023-21715 a Microsoft Publisher Security Features Bypass Vulnerability which we are describing below and CVE-2023-23376 a local Windows Common Log File System Driver Elevation of Privilege Vulnerability.
Krebs
Microsoft Patch Tuesday, February 2023 Edition
blogs_krebs·2023-02-14·CVSS 7.3
CVE-2023-23376 [HIGH] Microsoft Patch Tuesday, February 2023 Edition
Microsoft is sending the world a whole bunch of love today, in the form of patches to plug dozens of security holes in its Windows operating systems and other software. This year’s special Valentine’s Day Patch Tuesday includes fixes for a whopping three different “zero-day” vulnerabilities that are already being used in active attacks.
Microsoft’s security advisories are somewhat sparse with details about the zero-day bugs. Redmond flags CVE-2023-23376 as an “Important” elevation of privilege vulnerability in the Windows Common Log File System Driver, which is present in Windows 10 and 11 systems, as well as many server versions of Windows.
“Sadly, there’s just a little solid information about this privilege escalation,” said Dustin Childs, head of threat awareness at Trend Micro’s Zero
Crowdstrike
February 2023 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] February 2023 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Crowdstrike
February 2023 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] February 2023 Patch Tuesday: Updates and Analysis
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
2023-02-14
Published
Exploited in the wild