logo

Vulnerabilities in Microsoft 365 Apps

ID: e9199eaa-823d-5bc9-be75-72163ff78807

STIX ID: report--e9199eaa-823d-5bc9-be75-72163ff78807

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report analyzes how Microsoft’s patch for CVE-2023-29344 (affecting FreeImage used in MSOSPECTRE.DLL) disabled only SKP files of the MFC type while leaving VFF-type SKP files able to trigger the same FreeImage flaws; the author details a PoC that modifies embedded ZIP image data, updates CRC/size fields and recalculates a VFF checksum to bypass the patch and reproduce numerous vulnerable conditions, leading to the assignation of CVE-2023-33146 and Microsoft subsequently disabling SketchUp insertion in Office as a mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.