cbcvebase.
CVE-2023-21716
published 2023-02-14

CVE-2023-21716: Microsoft Word Remote Code Execution Vulnerability

PriorityP189critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
82.30%
99.6th percentile
Microsoft Word Remote Code Execution Vulnerability

Affected

39 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftmicrosoft_365_apps_for_enterprise>= 16.0.1 < https://aka.ms/OfficeSecurityReleaseshttps://aka.ms/OfficeSecurityReleases
microsoftmicrosoft_office_2019>= 19.0.0 < https://aka.ms/OfficeSecurityReleaseshttps://aka.ms/OfficeSecurityReleases
microsoftmicrosoft_office_2019_for_mac>= 16.0.0 < 16.70.2302120116.70.23021201
microsoftmicrosoft_office_ltsc_2021>= 16.0.1 < https://aka.ms/OfficeSecurityReleaseshttps://aka.ms/OfficeSecurityReleases
microsoftmicrosoft_office_ltsc_for_mac_2021>= 16.0.1 < 16.70.2302120116.70.23021201
microsoftmicrosoft_office_online_server>= 16.0.1 < 16.0.10395.2000116.0.10395.20001
microsoftmicrosoft_office_web_apps_server_2013_service_pack_1>= 15.0.1 < 15.0.5529.100015.0.5529.1000
microsoftmicrosoft_sharepoint_enterprise_server_2013_service_pack_1>= 15.0.0 < 15.0.5529.100015.0.5529.1000
microsoftmicrosoft_sharepoint_enterprise_server_2016>= 16.0.0 < 16.0.5383.100016.0.5383.1000
microsoftmicrosoft_sharepoint_foundation_2013_service_pack_1>= 15.0.0 < 15.0.5529.100015.0.5529.1000
microsoftmicrosoft_sharepoint_server_2019>= 16.0.0 < 16.0.10395.2000116.0.10395.20001
microsoftmicrosoft_sharepoint_server_subscription_edition>= 16.0.0 < 16.0.15601.2047816.0.15601.20478
microsoftmicrosoft_word_2013_service_pack_1>= 15.0.1 < 15.0.5529.100015.0.5529.1000
microsoftmicrosoft_word_2016>= 16.0.1 < 16.0.5383.100016.0.5383.1000
microsoftoffice
microsoftoffice_long_term_servicing_channel
microsoftoffice_online_server
microsoftoffice_web_apps
microsoftsharepoint_enterprise_server
microsoftsharepoint_enterprise_server
microsoftsharepoint_foundation
microsoftsharepoint_server
microsoftsharepoint_server_subscription_edition_language_pack>= 16.0.0 < 16.0.15601.2047816.0.15601.20478
microsoftword
msrcmicrosoft_365_apps

Detection & IOCsextracted from sources · hover to see the quote

pathHKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Word\Security\FileBlock
pathHKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\Security\FileBlock
  • The vulnerability is triggered by RTF files containing an abnormally large font table definition; detect RTF files with unusually large \fonttbl entries delivered via email or web.
  • The Preview Pane in Outlook is an attack vector — exploitation can occur without the user opening or downloading the attachment; monitor Outlook preview pane rendering of RTF content.
  • Delivery vector is a malicious RTF file sent as an email attachment; alert on inbound emails carrying .rtf attachments, especially from external/untrusted senders.
  • Monitor registry keys HKCU\Software\Microsoft\Office\15.0\Word\Security\FileBlock and HKCU\Software\Microsoft\Office\16.0\Word\Security\FileBlock for RtfFiles DWORD value; absence of value=2 indicates the RTF file-block mitigation is not applied.
  • ·Configuring Outlook to read email in plain text removes pictures, specialized fonts, animations, and other rich content, and may cause unexpected behavior in custom code solutions that rely on the object model.
  • ·SharePoint Enterprise Server 2013 SP1 customers should install either the cumulative update (ubersrv13) OR both security updates (sts2013 AND loc2013), not necessarily all listed updates.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
vendor_msrc9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.