CVE-2023-2171414.02.2023, 20:15Microsoft Office Information Disclosure VulnerabilityEnginsightProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVectorNISTPrimary5.5 MEDIUMLOCALLOWNONECVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NBase ScoreCVSS 3.xEPSS ScorePercentile: UnknownAffected Products (NVD)VendorProductVersionmicrosoft365_apps-𝑥= Vulnerable software versionsCommon Weakness EnumerationCWE-125 - Out-of-bounds ReadThe software reads data past the end, or before the beginning, of the intended buffer.CWE-668 - Exposure of Resource to Wrong SphereThe product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.Referenceshttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21714https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21714