CVE-2023-21715

HIGH KEV

Microsoft Publisher - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2023-21715 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added February 14, 2023.

Description

Microsoft Publisher Security Feature Bypass Vulnerability

References (2)

Core 2

Scores

CVSS v3 7.3
EPSS 0.0048
EPSS Percentile 65.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2023-02-14
VulnCheck KEV 2023-02-14
InTheWild.io 2023-02-14
ENISA EUVD EUVD-2023-25882
CWE
CWE-863
Status published
Products (1)
microsoft/365_apps
Published Feb 14, 2023
KEV Added Feb 14, 2023
Tracked Since Feb 18, 2026