CVE-2022-29109
CVSS 3.1 Score 7.8 of 10 (high)
Details
Summary
CVE-2022-29109 is a remote code execution vulnerability affecting Microsoft Excel. Maliciously crafted Excel files can manipulate the Object Linking and Embedding (OLE) functionality to execute arbitrary code on a victim's system, potentially allowing an attacker to gain control and steal sensitive information or install malware. Microsoft has released a patch to address this issue, and users are strongly encouraged to apply it as soon as possible to protect against potential exploitation. This vulnerability poses a significant risk to organizations and individuals who rely on Excel for data processing, particularly those who receive untrusted files from external sources.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Office
- Microsoft 365 Apps
Affected Vendors
- Microsoft