Does CVE-2023-36884 impact Windows 10 with office 365 2302 or later installed?

N T 25 Reputation points
2023-07-26T00:18:41.7866667+00:00

Does CVE-2023-36884 impact Windows 10 with office 365 2302 or later installed?

Microsoft 365 and Office | Install, redeem, activate | For business | Windows
Windows for business | Windows Client for IT Pros | User experience | Other
0 comments No comments
{count} votes

Accepted answer
  1. S.Sengupta 24,871 Reputation points MVP
    2023-07-26T01:27:53.5666667+00:00

    Microsoft 365 Semi-Annual Channel version 2302 (and all later versions) are protected from this vulnerability. Please see Update history for Microsoft 365 Apps (listed by date) for information about those channels and their versions.

    1 person found this answer helpful.
    0 comments No comments

2 additional answers

Sort by: Most helpful
  1. Wesley Li-MSFT 4,576 Reputation points Microsoft External Staff
    2023-07-26T08:00:51.01+00:00

    Hello

    Yes, the vulnerability CVE-2023-36884 impacts Microsoft Office and Windows HTML. Microsoft is investigating reports of a series of remote code execution vulnerabilities impacting Windows and Office products. However, I couldn’t find any specific information about whether it impacts Windows 10 with Office 365 version 2302 or later. You can check the Microsoft Security Response Center for updates and more information. It’s always a good idea to keep your software up to date with the latest security patches.

    https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36884


  2. N T 25 Reputation points
    2023-07-26T12:48:17.5333333+00:00

    Per the link provided,

    https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36884

    You will see the following as part of the answer in the FAQ section.

    "Microsoft 365 Semi-Annual Channel version 2302 (and all later versions) are protected from this vulnerability.."My concern is if you do not have office installed on the computer, like on servers, are you still vulnerable to this vulnerability? The article above indicates that all Microsoft operating systems are vulnerable, but also indicates the following:

    "Microsoft is investigating reports of a series of remote code execution vulnerabilities impacting Windows and Office products. Microsoft is aware of targeted attacks that attempt to exploit these vulnerabilities by using specially-crafted Microsoft Office documents.

    An attacker could create a specially crafted Microsoft Office document that enables them to perform remote code execution in the context of the victim. However, an attacker would have to convince the victim to open the malicious file."

    I am still wondering if this impacts all windows operating systems even if office is not installed.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.