CVE-2023-23391
published 2023-03-14CVE-2023-23391: Office for Android Spoofing Vulnerability Office for Android Spoofing Vulnerability
medium5.5CVSS 3.1
AVLACLPRNUIRSUCNIHAN
EPSS
0.65%
47.3th percentile
Office for Android Spoofing Vulnerability
Office for Android Spoofing Vulnerability
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_office_for_android | >= 16.0.1 < 16.0.16026.20172 | 16.0.16026.20172 |
| msrc | microsoft_office_for_android | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
cvelistv55.5MEDIUM
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CVEList
Office for Android Spoofing Vulnerability
cvelistv5·2023-03-14·CVSS 5.5
CVE-2023-23391 [MEDIUM] CWE-23 Office for Android Spoofing Vulnerability
Office for Android Spoofing Vulnerability
Office for Android Spoofing Vulnerability
Microsoft
Office for Android Spoofing Vulnerability
vendor_msrc·2023-03-14·CVSS 5.5
CVE-2023-23391 [MEDIUM] CWE-23 Office for Android Spoofing Vulnerability
Office for Android Spoofing Vulnerability
FAQ: According to the CVSS metric, the attack vector is local (AV:L) and user interaction is required (UI:R), what does that mean for this vulnerability?
The attack itself is carried out locally. For example, when the score indicates that the Attack Vector is Local and User Interaction is Required, this could describe an exploit in which an attacker, through social engineering, convinces a victim to click on a local file path link or download and run a malicious application or file.
FAQ: What is the nature of the spoofing?
An attacker could manipulate a malicious link, application, or file to disguise it as a legitimate link or file to trick the victim.
Office for Android: Office for Android
Microsoft: Microsoft
Customer Action Required: Yes
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-03-14
Published