CVE-2024-43616

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Oct 8, 2024
Updated: Oct 21, 2024
CWE ID 426

Summary

CVE-2024-43616 is a newly disclosed remote code execution vulnerability affecting Microsoft Office. Hackers can exploit this weakness by manipulating specially crafted Office files, potentially gaining control over affected systems. Successful exploitation could lead to the installation of malware, unauthorized access, or data theft. Users are advised to update their Microsoft Office software as soon as possible to mitigate this risk. The exact cause and exploit details have not been disclosed, but it's recommended to exercise caution when opening unexpected Office files from untrusted sources.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Office
  • Microsoft Office Long Term Servicing Channel
  • Microsoft 365 Apps
  • Microsoft Office 2019
  • Microsoft Office 365

Affected Vendors

  • Microsoft