CVE-2023-33137
HIGHMicrosoft Office - Remote Code Execution via Double Free
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-33137. PoCs published by nu11secur1ty.
AI-analyzed exploit summary The exploit leverages a VBA macro in Microsoft Excel to execute arbitrary commands via a POST request to an attacker-controlled server, downloading and executing a malicious batch file. It demonstrates a remote code execution (RCE) vulnerability in Microsoft 365 MSO (Version 2305 Build 16.0.16501.20074) 32-bit.
Description
Microsoft Excel Remote Code Execution Vulnerability
Exploits (1)
The exploit leverages a VBA macro in Microsoft Excel to execute arbitrary commands via a POST request to an attacker-controlled server, downloading and executing a malicious batch file. It demonstrates a remote code execution (RCE) vulnerability in Microsoft 365 MSO (Version 2305 Build 16.0.16501.20074) 32-bit.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H