CVE-2024-43600
published 2024-12-12CVE-2024-43600: Microsoft Office Elevation of Privilege Vulnerability
PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
1.23%
65.4th percentile
Microsoft Office Elevation of Privilege Vulnerability
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_office_2016 | >= 16.0.0 < 16.0.5478.1000 | 16.0.5478.1000 |
| microsoft | office | — | — |
| msrc | microsoft_office_2016 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Office Elevation of Privilege Vulnerability
vendor_msrc·2024-12-10·CVSS 7.8
CVE-2024-43600 [HIGH] CWE-284 Microsoft Office Elevation of Privilege Vulnerability
Microsoft Office Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
FAQ: Is the Preview Pane an attack vector for this vulnerability?
No, the Preview Pane is not an attack vector.
FAQ: There are multiple update packages available for some of the affected software. Do I need to install all the updates listed in the Security Updates table for the software?
Yes. Customers should apply all updates offered for the software installed on their systems. If multiple updates apply, they can be installed in any order.
Microsoft Office: Microsoft Office
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of
GHSA
GHSA-5ggf-wr65-v75x: Microsoft Office Elevation of Privilege Vulnerability
ghsa_unreviewed·2024-12-12
CVE-2024-43600 [HIGH] CWE-284 GHSA-5ggf-wr65-v75x: Microsoft Office Elevation of Privilege Vulnerability
Microsoft Office Elevation of Privilege Vulnerability
No detection rules found.
No public exploits indexed.
2024-12-12
Published