Skip to main content

Microsoft discloses Office zero-day, still working on a patch


Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54

See Also - Microsoft August 2024 Early Security Updates

 

August 9, 2024 By Sergiu Gatlan

 

Microsoft Office

​Microsoft has disclosed a high-severity zero-day vulnerability affecting Office 2016 and later, which is still waiting for a patch.

Tracked as CVE-2024-38200, this security flaw is caused by an information disclosure weakness that enables unauthorized actors to access protected information such as system status or configuration data, personal info, or connection metadata.

The zero-day impacts multiple 32-bit and 64-bit Office versions, including Office 2016, Office 2019, Office LTSC 2021, and Microsoft 365 Apps for Enterprise.

Even though Microsoft's exploitability assessment says that exploitation of CVE-2024-38200 is less likely, MITRE has tagged the likelihood of exploitation for this type of weakness as highly probable.

 

>>Full Article<<

0 replies

Be the first to reply!

Reply