← Back to browse · API

CVE-2023-21715

Severity
HIGH
CVSS
7.3
EPSS
0.12011
Risk score
58.4
CISA KEV
Yes
PoC
No
Published
2023-02-14
Modified
2023-02-14
First seen
2026-08-07
Aliases
EUVD-2023-25882, GHSA-9GF3-6WPF-HGPX
Products
Microsoft:Microsoft 365 Apps for Enterprise 16.0.1 <https://aka.ms/OfficeSecurityReleases, Microsoft:Office
Sources
euvd EUVD-2023-25882
cisa.gov CVE-2023-21715

Description

Microsoft Office Publisher contains a security feature bypass vulnerability that allows for a local, authenticated attack on a targeted system.

References