by @jakaba
20 Nov 2023

MS Office and Windows HTML RCE (CVE-2023-36884)

by @jakaba
20 Nov 2023

MS Office and Windows HTML RCE (CVE-2023-36884)

CVEs

7.5 High Severity

OS

W12
10.0.22000.2713.*
10.0.22000.2713.*
10.0.22000.2652.*
10.0.22000.2600.*
10.0.22000.2600.*
10.0.22000.2482.*
10.0.22000.2482.*
10.0.22000.2245.*
10.0.22000.2245.*
10.0.22000.2360.*
W12
10.0.19045.3930.*
10.0.19045.3930.*
10.0.19045.3930.*
10.0.19045.3803.*
10.0.19045.3693.*
10.0.19045.3693.*
10.0.19045.3693.*
10.0.19045.3570.*
10.0.19045.3570.*
10.0.19045.3570.*
W12
10.0.19044.4046.*
10.0.19044.2788.*
10.0.19044.2788.*
10.0.19044.2788.*
10.0.19044.3803.*
10.0.19044.3803.*
10.0.19044.3803.*
10.0.19044.3693.*
10.0.19044.3693.*
10.0.19044.3693.*
10.0.17763.5329.*
10.0.17763.4010.*
18411.*
18409.*
18409.*
18409.2019
1909.*
1903.*
*.*
1809.2019
10.0.14393.6614.*
10.0.14393.5717.*
20H2.*
1909.*
1903.*
*.*
2019.*
1803.*
1709.*
1607.*
6.2.9200.24116.*
R2.*
R2.*
R2.SP1
R2.*
R2.*
R2.*
R2.*
R2.SP1
R2.*

Apps

Word
WordMicrosoft
16.0.17328.20184.*
16.0.5435.*
16.0.17328.20162.*
16.0.17425.20008.*
16.0.17328.20068.*
16.0.5435.1000.*
16.0.17231.20236.*
16.0.17231.20194.*
16.0.17126.20132.*
16.0.17029.20108.*
Office
OfficeMicrosoft
16.0.17328.*
16.0.17425.20070.*
16.0.17328.20184.*
16.0.5435.*
16.0.17328.20162.*
16.0.17328.20068.*
16.0.17231.20236.*
16.0.17231.20194.*
16.0.5422.*
18.2311.1071.0.*

Screenshots from the blog posts

images/cln3167kl61me1io9dpt2aivn.pngimages/cln3167kl61me1io9dpt2aivn.png

Summary

This article delves deeper into the malevolent OOXML and embedded Rich Text Format (RTF) document exploit deployed in targeted attacks against government entities. We look at the anatomy of RTF documents and will endeavor to programmatically reconstruct the malicious document using the same technique and complete it with a sample code. After that, we will try to understand the attack chain too.

Description

users/photos/clj8b3h1k16g10uoihwvzgsxi.png

@jakaba

41 posts

Total vcoins

38.8K

Social media links

Comments (1)