CVE-2023-23396
published 2023-03-14CVE-2023-23396: Microsoft Excel Denial of Service Vulnerability Microsoft Excel Denial of Service Vulnerability
medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
3.83%
89.0th percentile
Microsoft Excel Denial of Service Vulnerability
Microsoft Excel Denial of Service Vulnerability
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_office_online_server | >= 16.0.1 < 16.0.10396.20000 | 16.0.10396.20000 |
| microsoft | microsoft_office_web_apps_server_2013_service_pack_1 | >= 15.0.1 < 15.0.5537.1000 | 15.0.5537.1000 |
| msrc | microsoft_office_online_server | — | — |
| msrc | microsoft_office_web_apps_server_2013_service_pack_1 | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
cvelistv56.5MEDIUM
vendor_msrc6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Excel Denial of Service Vulnerability
vendor_msrc·2023-03-14·CVSS 6.5
CVE-2023-23396 [MEDIUM] CWE-400 Microsoft Excel Denial of Service Vulnerability
Microsoft Excel Denial of Service Vulnerability
FAQ: How could an attacker exploit this vulnerability?
The attacker could exploit this vulnerability by convincing a victim to open a specially crafted XLSX file which when opened would cause a denial-of-service condition for other processes running on that machine.
FAQ: Is the Preview Pane an attack vector for this vulnerability?
No, the Preview Pane is not an attack vector.
FAQ: According to the CVSS metric, the attack vector is network (AV:N). What does that mean for this vulnerability?
An attacker could trigger this vulnerability by convincing a victim to access a malicious file via a network connection or by downloading and opening the malicious file locally. In the worst case scenario, the malicious file could be triggered with a web
CVEList
Microsoft Excel Denial of Service Vulnerability
cvelistv5·2023-03-14·CVSS 6.5
CVE-2023-23396 [MEDIUM] CWE-400 Microsoft Excel Denial of Service Vulnerability
Microsoft Excel Denial of Service Vulnerability
Microsoft Excel Denial of Service Vulnerability
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-03-14
Published