ZeroHour

CVE-2023-36761

KEVmass1

Information Disclosure Flaw in Microsoft Word Actively Exploited (CVE-2023-36761)

CISA: Microsoft Word Information Disclosure Vulnerability

CVSS 3.1
6.5 medium
EPSS
20%p97
Published
()
KEV added
AI analysis

CVE-2023-36761 is an information disclosure vulnerability in Microsoft Word caused by improper input validation (CWE-20). It is triggered when a user opens a specially crafted document, requiring user interaction but no authentication or special privileges, per the CVSS vector (AV:N/PR:N/UI:R). A successful attacker gains access to sensitive information from the affected system, with public reporting indicating the flaw can leak authentication material such as NTLM credentials. Anyone running affected versions of Word, including Word within Microsoft 365 Apps, Microsoft Office, and Office LTSC, is exposed, and the flaw was fixed in Microsoft's September 2023 Patch Tuesday updates. The vulnerability was exploited as a zero-day before patching: CISA added it to the Known Exploited Vulnerabilities catalog on September 12, 2023, and its EPSS score of 19.0% (97th percentile) signals elevated near-term exploitation risk.

What to do: Apply Microsoft's September 2023 security updates for Microsoft 365 Apps, Office, Office LTSC, and Word immediately, per vendor instructions and CISA KEV requirements. Until patched, treat unsolicited documents as untrusted and consider restricting outbound SMB/NTLM traffic to limit credential leakage. Given confirmed in-the-wild exploitation and no known public PoC, prioritize this KEV remediation and verify patch deployment across endpoints.

Affected
Microsoft WordSupported versions per Microsoft's advisory; fixed in September 2023 security updates (no specific version ranges provided in source data)
Microsoft 365 Apps (Word component)Supported versions; fixed in September 2023 security updates
Microsoft OfficeSupported versions; fixed in September 2023 security updates
Microsoft Office Long Term Servicing Channel (LTSC)Supported versions; fixed in September 2023 security updates
Estimated exposure
masshundreds of millions of users/devices (Word ships with Microsoft 365 and Office across enterprise and consumer fleets) — Microsoft Word/Office is among the most widely deployed desktop applications worldwide, with an installed base measured in the hundreds of millions of devices, so any unpatched Office fleet is exposed through the open-a-malicious-document…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Word Information Disclosure Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Word
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
365 apps, office, office long term servicing channel, word
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news