CVE-2024-41165
published 2024-12-18CVE-2024-41165: A library injection vulnerability exists in Microsoft Word 16.83 for macOS. A specially crafted library can leverage Word's access privileges, leading to a…
PriorityP351critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.74%
50.2th percentile
A library injection vulnerability exists in Microsoft Word 16.83 for macOS. A specially crafted library can leverage Word's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this vulnerability and then make use of the vulnerable application's permissions.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | word | — | — |
| microsoft | word | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Talos
How multiple vulnerabilities in Microsoft apps for macOS pave the way to stealing permissions
blogs_talos·2024-08-19·CVSS 7.1
[HIGH] How multiple vulnerabilities in Microsoft apps for macOS pave the way to stealing permissions
## How multiple vulnerabilities in Microsoft apps for macOS pave the way to stealing permissions
Cisco Talos has identified eight vulnerabilities in Microsoft applications for the macOS operating system.
An adversary could exploit these vulnerabilities by injecting malicious libraries into Microsoft's applications to gain their entitlements and user-granted permissions.
Permissions regulate whether an app can access resources such as the microphone, camera, folders, screen recording, user input and more. So if an adversary were to gain access to these, they could potentially leak sensitive information or, in the worst case, escalate privileges.
This post also provides an overview of the macOS security model and illustrates how vulnerabilities within macOS applications could be exploite
Talos
How multiple vulnerabilities in Microsoft apps for macOS pave the way to stealing permissions
blogs_talos·2024-08-19·CVSS 7.1
[HIGH] How multiple vulnerabilities in Microsoft apps for macOS pave the way to stealing permissions
- Cisco Talos has identified eight vulnerabilities in Microsoft applications for the macOS operating system.
- An adversary could exploit these vulnerabilities by injecting malicious libraries into Microsoft's applications to gain their entitlements and user-granted permissions.
- Permissions regulate whether an app can access resources such as the microphone, camera, folders, screen recording, user input and more. So if an adversary were to gain access to these, they could potentially leak sensitive information or, in the worst case, escalate privileges.
- This post also provides an overview of the macOS security model and illustrates how vulnerabilities within macOS applications could be exploited by adversaries to steal app permissions.
Cisco Talos recently conducted an analysis of mac
2024-12-18
Published