CVE-2023-33149
published 2023-07-11CVE-2023-33149: Microsoft Office Graphics Remote Code Execution Vulnerability
PriorityP339high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.63%
46.3th percentile
Microsoft Office Graphics Remote Code Execution Vulnerability
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_365_apps_for_enterprise | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_2013_service_pack_1 | >= 15.0.0 < 15.0.5571.1000 | 15.0.5571.1000 |
| microsoft | microsoft_office_2016 | >= 16.0.0 < 16.0.5404.1000 | 16.0.5404.1000 |
| microsoft | microsoft_office_2019 | >= 19.0.0 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_2019_for_mac | >= 16.0.0 < 16.75.23070901 | 16.75.23070901 |
| microsoft | microsoft_office_ltsc_2021 | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_ltsc_for_mac_2021 | >= 16.0.1 < 16.75.23070901 | 16.75.23070901 |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office_long_term_servicing_channel | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_32-bit_systems | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_64-bit_systems | — | — |
| msrc | microsoft_office_2013_rt_service_pack_1 | — | — |
| msrc | microsoft_office_2013_service_pack_1 | — | — |
| msrc | microsoft_office_2016 | — | — |
| msrc | microsoft_office_2019_for_32-bit_editions | — | — |
| msrc | microsoft_office_2019_for_64-bit_editions | — | — |
| msrc | microsoft_office_2019_for_mac | — | — |
| msrc | microsoft_office_ltsc_2021_for_32-bit_editions | — | — |
| msrc | microsoft_office_ltsc_2021_for_64-bit_editions | — | — |
| msrc | microsoft_office_ltsc_for_mac_2021 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Microsoft Office 365 Apps for Enterprise/2013 SP1/2016/LTSC 2021 Graphics use after free
vuldb·2026-05-19·CVSS 7.8
CVE-2023-33149 [HIGH] Microsoft Office 365 Apps for Enterprise/2013 SP1/2016/LTSC 2021 Graphics use after free
A vulnerability was found in Microsoft Office 2013 SP1/2016/LTSC 2021/365 Apps for Enterprise and classified as critical. This issue affects some unknown processing of the component Graphics. The manipulation results in use after free.
This vulnerability is reported as CVE-2023-33149. The attack can be launched remotely. No exploit exists.
It is best practice to apply a patch to resolve this issue.
GHSA
GHSA-mh4q-8w9c-v3h4: Microsoft Office Graphics Remote Code Execution Vulnerability
ghsa_unreviewed·2023-07-11
CVE-2023-33149 [HIGH] GHSA-mh4q-8w9c-v3h4: Microsoft Office Graphics Remote Code Execution Vulnerability
Microsoft Office Graphics Remote Code Execution Vulnerability
Microsoft
Microsoft Office Graphics Remote Code Execution Vulnerability
vendor_msrc·2023-07-11·CVSS 7.8
CVE-2023-33149 [HIGH] CWE-416 Microsoft Office Graphics Remote Code Execution Vulnerability
Microsoft Office Graphics Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
An attacker must send the user a malicious file and convince them to open it.
FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?
The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally. This means an attacker or victim needs to execute code from the local machine to exploit the vulnerability.
FAQ: There are multiple update packages available for some of the affected software. Do I need to ins
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-07-11
Published