KLA12480
Multiple vulnerabilities in Microsoft Office

Обновлено: 16/03/2022
Дата обнаружения
08/03/2022
Уровень угрозы
High
Описание

Multiple vulnerabilities were found in Microsoft Office. Malicious users can exploit these vulnerabilities to bypass security restrictions, execute arbitrary code, spoof user interface, obtain sensitive information.

Below is a complete list of vulnerabilities:

  1. A security feature bypass vulnerability in Microsoft Word can be exploited remotely to bypass security restrictions.
  2. A remote code execution vulnerability in Microsoft Office Visio can be exploited remotely to execute arbitrary code.
  3. A tampering vulnerability in Microsoft Office Word can be exploited remotely to spoof user interface.
  4. An information disclosure vulnerability in Skype Extension for Chrome can be exploited remotely to obtain sensitive information.
  5. A remote code execution vulnerability in Microsoft Office Visio can be exploited remotely to execute arbitrary code..
Пораженные продукты

Microsoft 365 Apps for Enterprise for 32-bit Systems
Microsoft Office LTSC 2021 for 64-bit editions
Microsoft Word 2016 (64-bit edition)
Microsoft 365 Apps for Enterprise for 64-bit Systems
Skype Extension for Chrome
Microsoft Office LTSC 2021 for 32-bit editions
Microsoft Word 2013 Service Pack 1 (64-bit editions)
Microsoft Office 2019 for Mac
Microsoft Office 2019 for 64-bit editions
Microsoft Office LTSC for Mac 2021
Microsoft Office 2019 for 32-bit editions
Microsoft Word 2016 (32-bit edition)
Microsoft Word 2013 Service Pack 1 (32-bit editions)
Microsoft Word 2013 RT Service Pack 1

Решение

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Первичный источник обнаружения
CVE-2022-24462
CVE-2022-24510
CVE-2022-24461
CVE-2022-24511
CVE-2022-24522
CVE-2022-24509
Оказываемое влияние
?
ACE 
[?]

OSI 
[?]

SB 
[?]

SUI 
[?]
Связанные продукты
Microsoft Office
Microsoft Word
CVE-IDS
KB list

5002139
5002068

Microsoft official advisories
Microsoft Security Update Guide
Узнай статистику распространения уязвимостей в твоем регионе