Vulnerabilities in Microsoft 365 Apps
ID: e9199eaa-823d-5bc9-be75-72163ff78807
STIX ID: report--e9199eaa-823d-5bc9-be75-72163ff78807
Feed Name: Zscaler Security Research Blog
This report analyzes how Microsoft’s patch for CVE-2023-29344 (affecting FreeImage used in MSOSPECTRE.DLL) disabled only SKP files of the MFC type while leaving VFF-type SKP files able to trigger the same FreeImage flaws; the author details a PoC that modifies embedded ZIP image data, updates CRC/size fields and recalculates a VFF checksum to bypass the patch and reproduce numerous vulnerable conditions, leading to the assignation of CVE-2023-33146 and Microsoft subsequently disabling SketchUp insertion in Office as a mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
