logo

Microsoft: Unpatched Office zero-day [CVE-2023-36884]

ID: 8d1c447d-49b6-593e-8463-f5f4fdce9171

STIX ID: report--8d1c447d-49b6-593e-8463-f5f4fdce9171

Feed Name: ThreatLocker Blog

Threat Score
80/100

Date Published: 2025-01-09

Date Updated: 2026-05-01

...
...

Microsoft disclosed CVE-2023-36884, a remote code execution vulnerability in Windows and Office that can be exploited by crafted Office documents which execute code even with macros disabled or in Protected View; attackers use this to install the RomCom backdoor (delivered as Calc.exe and persisted as security.dll) that registers to a C2, exfiltrates system information, and accepts commands. The report lists affected Office executables and recommends mitigations including blocking Office from creating child processes (Defender for Office or a registry key) and highlights ThreatLocker's ringfencing as a preventative control.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.