CVE-2023-29335
published 2023-05-09CVE-2023-29335: Microsoft Word Security Feature Bypass Vulnerability
PriorityP341high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
EPSS
1.17%
64.0th percentile
Microsoft Word Security Feature Bypass Vulnerability
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_365_apps_for_enterprise | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_2019 | >= 19.0.0 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_ltsc_2021 | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_word_2013_service_pack_1 | >= 15.0.1 < 15.0.5553.1000 | 15.0.5553.1000 |
| microsoft | microsoft_word_2016 | >= 16.0.1 < 16.0.5395.1000 | 16.0.5395.1000 |
| microsoft | office | — | — |
| microsoft | office_long_term_servicing_channel | — | — |
| microsoft | windows_10_1507 | < 10.0.10240.19926 | 10.0.10240.19926 |
| microsoft | windows_10_1607 | < 10.0.14393.5921 | 10.0.14393.5921 |
| microsoft | windows_10_1809 | < 10.0.17763.4377 | 10.0.17763.4377 |
| microsoft | windows_10_20h2 | < 10.0.19042.2965 | 10.0.19042.2965 |
| microsoft | windows_10_21h2 | < 10.0.19044.2965 | 10.0.19044.2965 |
| microsoft | windows_10_22h2 | < 10.0.19045.2965 | 10.0.19045.2965 |
| microsoft | windows_11_21h2 | < 10.0.22000.1936 | 10.0.22000.1936 |
| microsoft | windows_11_22h2 | < 10.0.22000.1702 | 10.0.22000.1702 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2012 | — | — |
| microsoft | word | — | — |
| microsoft | word | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_32-bit_systems | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_64-bit_systems | — | — |
| msrc | microsoft_office_2019_for_32-bit_editions | — | — |
| msrc | microsoft_office_2019_for_64-bit_editions | — | — |
| msrc | microsoft_office_ltsc_2021_for_32-bit_editions | — | — |
| msrc | microsoft_office_ltsc_2021_for_64-bit_editions | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Microsoft Office up to LTSC 2021 Word input validation
vuldb·2026-05-19·CVSS 7.5
CVE-2023-29335 [HIGH] Microsoft Office up to LTSC 2021 Word input validation
A vulnerability, which was classified as problematic, was found in Microsoft Office up to LTSC 2021. This impacts an unknown function of the component Word. The manipulation results in improper input validation.
This vulnerability was named CVE-2023-29335. The attack may be performed from remote. There is no available exploit.
It is advisable to implement a patch to correct this issue.
GHSA
GHSA-p6fp-wfwv-r5g8: Microsoft Word Security Feature Bypass Vulnerability
ghsa_unreviewed·2023-05-09
CVE-2023-29335 [HIGH] GHSA-p6fp-wfwv-r5g8: Microsoft Word Security Feature Bypass Vulnerability
Microsoft Word Security Feature Bypass Vulnerability
Microsoft
Microsoft Word Security Feature Bypass Vulnerability
vendor_msrc·2023-05-09·CVSS 7.5
CVE-2023-29335 [HIGH] CWE-20 Microsoft Word Security Feature Bypass Vulnerability
Microsoft Word Security Feature Bypass Vulnerability
FAQ: What kind of security feature could be bypassed by successfully exploiting this vulnerability?
This vulnerability could allow an attacker to bypass specific functionality of the Office Protected View.
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to gather information specific to the environment and take additional actions prior to exploitation to prepare the target environment.
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
Exploitation of the vulnerability requires that a user open a specially crafted file.
In an email atta
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-05-09
Published