CVE-2023-21716 is a critical Remote Code Execution (RCE) vulnerability affecting Microsoft Word and various Microsoft Office and SharePoint products. With a CVSS score of 9.8, it presents a severe risk, allowing unauthenticated attackers to execute arbitrary code with high impact on confidentiality, integrity, and availability. While not currently listed on CISA's KEV catalog, its high EPSS score and significant community discussion (20 mentions) indicate a strong potential for exploitation. Although no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available, media coverage confirms its critical nature and the release of a Proof-of-Concept.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2019:*:*:*:*:macos:*:* | ||
2021CPE matchmatch criteria | cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:macos:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:office_online_server:2016:*:*:*:*:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:office_web_apps:2013:sp1:*:*:*:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_enterprise_server:2013:sp1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.