News / Tech News |
Discovery of the CVE-2023-36884 vulnerability in Microsoft Windows and Office
On Tuesday July 11, 2023, Microsoft announced the existence of a vulnerability referenced CVE-2023-36884 in several versions of Windows and Office products.
Microsoft, the publisher of the affected products, confirms that the vulnerability has been actively exploited in a targeted manner.
No fix is currently available but mitigations have been proposed.
The CVE-2023-36884 vulnerability allows an attacker to execute arbitrary code remotely in the user context using a Microsoft Office document.
In less technical terms, a security issue with Microsoft Office products allows an attacker to remotely execute code in a device, through a specially crafted and previously transmitted document using social engineering technique .
An attacker could create a specially crafted Microsoft Office document that would allow him to remotely execute code on the victim's device, however, the attacker would have to convince the victim to open the malicious file.