CVE-2024-43609
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Oct 8, 2024
Updated: Oct 17, 2024
CWE ID 200
Summary
CVE-2024-43609 is a newly disclosed vulnerability affecting Microsoft Office. Attackers can exploit this spoofing vulnerability to manipulate document properties, deceiving users into believing they are opening a trusted file. This could potentially lead to the disclosure of sensitive information or the installation of malware. Users are advised to exercise caution when opening unexpected or unverified files and to ensure their Microsoft Office software is up-to-date with the latest security patches.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Office
- Microsoft 365 Apps
- Microsoft Office Long Term Servicing Channel
- Microsoft Office 365
Affected Vendors
- Microsoft