@htmdcommunity
  @htmdcommunity
HTMD Community | Zero Day Office Vulnerability CVE-2023-36884 without a FIX until now @htmdcommunity | Uploaded 1 year ago | Updated 1 day ago
Zero Day Office Vulnerability CVE-2023-36884. An attacker could create a specially crafted Microsoft Office document that enables them to perform remote code execution in the context of the victim. All you want to know about this Vulnerability. Impacted Office Versions with CVE-2023-36884 Vulnerability

#Vulnerability #ZeroDay #patchtuesday #microsoft365 #officeapps #securityissue

FIX Office and Windows HTML Remote Code Execution Zero Day Vulnerability CVE-2023-36884 - https://www.anoopcnair.com/zero-day-office-windows-html-remote-code/

An attacker would have to convince the victim to open the malicious file. This CVE vulnerability is related to Storm-0978 attacks, revealing financial and espionage motives topic.

==
Let’s check what are the impacted Office App versions with CVE-2023-36884 Vulnerability. Office and Windows HTML Remote Code Execution Zero-Day Vulnerability impact the following versions of Microsoft 365 Apps. If I’m running Office365 Semi-Annual Channel Extended, are we affected by this vulnerability?

Office365 Semi-Annual Channel Extended (specifically versions 2208 and 2202) is affected.
Microsoft 365 Apps Semi-Annual Channel Extended (specifically versions 2208 and 2202) are affected.
However, Microsoft 365 Semi-Annual Channel version 2302 (and all later versions) is protected from this vulnerability.

==

Storm-0978 attacks reveal financial and espionage motives - https://www.microsoft.com/en-us/security/blog/2023/07/11/storm-0978-attacks-reveal-financial-and-espionage-motives/

Office and Windows HTML Remote Code Execution Vulnerability https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36884

https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/attack-surface-reduction-rules-reference?view=o365-worldwide#block-all-office-applications-from-creating-child-processes
Zero Day Office Vulnerability CVE-2023-36884 without a FIX until now2023 MS Ignite Intune Sessions for Online Vs In-Person AttendeesWin32 App Isolation to improve security and Privacy of WindowsHTMD Newsletter 87 - Exciting News | Guides | Free Intune TenantsSecure Microsoft Edge Browser using Intune Security Policies1611 HTMD Top Intune Windows 365 News from MS Ignite 2023MDE Troubleshooting Tools | Microsoft Defender for EndpointIntune Remote Help available for OOBE screen during Windows Autopilot Scenario ⭐️New Windows Autopilot Device Preparation Experience using IntuneMVP Awards and Credly - What is going on? #mvpbuzzIntune App Deployment Automation using Microsoft Graph APIMS Defender for Endpoint License assignment options

Zero Day Office Vulnerability CVE-2023-36884 without a FIX until now @htmdcommunity

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER