CVE-2023-36761
KEVmass1Information Disclosure Flaw in Microsoft Word Actively Exploited (CVE-2023-36761)
CISA: Microsoft Word Information Disclosure Vulnerability
CVE-2023-36761 is an information disclosure vulnerability in Microsoft Word caused by improper input validation (CWE-20). It is triggered when a user opens a specially crafted document, requiring user interaction but no authentication or special privileges, per the CVSS vector (AV:N/PR:N/UI:R). A successful attacker gains access to sensitive information from the affected system, with public reporting indicating the flaw can leak authentication material such as NTLM credentials. Anyone running affected versions of Word, including Word within Microsoft 365 Apps, Microsoft Office, and Office LTSC, is exposed, and the flaw was fixed in Microsoft's September 2023 Patch Tuesday updates. The vulnerability was exploited as a zero-day before patching: CISA added it to the Known Exploited Vulnerabilities catalog on September 12, 2023, and its EPSS score of 19.0% (97th percentile) signals elevated near-term exploitation risk.
What to do: Apply Microsoft's September 2023 security updates for Microsoft 365 Apps, Office, Office LTSC, and Word immediately, per vendor instructions and CISA KEV requirements. Until patched, treat unsolicited documents as untrusted and consider restricting outbound SMB/NTLM traffic to limit credential leakage. Given confirmed in-the-wild exploitation and no known public PoC, prioritize this KEV remediation and verify patch deployment across endpoints.
| Microsoft Word | Supported versions per Microsoft's advisory; fixed in September 2023 security updates (no specific version ranges provided in source data) |
| Microsoft 365 Apps (Word component) | Supported versions; fixed in September 2023 security updates |
| Microsoft Office | Supported versions; fixed in September 2023 security updates |
| Microsoft Office Long Term Servicing Channel (LTSC) | Supported versions; fixed in September 2023 security updates |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft Word Information Disclosure Vulnerability
- Affected
- Microsoft Word
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- 365 apps, office, office long term servicing channel, word
- Weakness
- CWE-20
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N