logo

Office and Windows HTML Remote Code Execution vulnerability (CVE-2023-36884)

ID: b9eac12f-b678-523a-a7c0-8efc3893ba61

STIX ID: report--b9eac12f-b678-523a-a7c0-8efc3893ba61

Feed Name: ThreatLocker Blog

Threat Score
75/100

Date Published: 2025-01-03

Date Updated: 2026-05-01

...
...

CVE-2023-36884 is a critical zero-day RCE vulnerability affecting multiple Microsoft Office and some Windows versions that can be exploited by specially crafted Office documents; the report details affected versions, potential impacts (remote code execution, data theft, ransomware, persistence), Microsoft mitigation recommendations (Defender for Office 365, updates, and a FEATURE_BLOCK_CROSS_PROTOCOL_FILE_NAVIGATION registry mitigation) and ThreatLocker's Configuration Manager policy to deploy the recommended registry-based mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.