Microsoft Excel是美国微软(Microsoft)公司的一款Office套件中的电子表格处理软件。 Microsoft Office Excel存在资源管理错误漏洞。以下产品和版本受到影响:Microsoft Office 2019 for 32-bit editions,Microsoft Office 2019 for 64-bit editions,Microsoft Office Online Server,Microsoft 365 Apps for Enterprise for 3
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Microsoft | Microsoft 365 Apps for Enterprise | 16.0.1< https://aka.ms/OfficeSecurityReleases |
affected |
| Microsoft | Microsoft Excel 2013 Service Pack 1 | 15.0.0.0< 15.0.5501.1000 |
affected |
| Microsoft | Microsoft Excel 2016 | 16.0.0.0< 16.0.5369.1000 |
affected |
| Microsoft | Microsoft Office 2019 | 19.0.0< https://aka.ms/OfficeSecurityReleases |
affected |
| Microsoft | Microsoft Office LTSC 2021 | 16.0.1< https://aka.ms/OfficeSecurityReleases |
affected |
| Microsoft | Microsoft Office Online Server | 16.0.1< 16.0.10392.20000 |
affected |
| Microsoft | Microsoft Office Web Apps Server 2013 Service Pack 1 | 15.0.1< 15.0.5501.1000 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Microsoft | Microsoft 365 Apps for Enterprise | 16.0.1 ~ https://aka.ms/OfficeSecurityReleases | - |
|
| Microsoft | Microsoft Excel 2013 Service Pack 1 | 15.0.0.0 ~ 15.0.5501.1000 | - |
|
| Microsoft | Microsoft Excel 2016 | 16.0.0.0 ~ 16.0.5369.1000 | - |
|
| Microsoft | Microsoft Office 2019 | 19.0.0 ~ https://aka.ms/OfficeSecurityReleases | - |
|
| Microsoft | Microsoft Office LTSC 2021 | 16.0.1 ~ https://aka.ms/OfficeSecurityReleases | - |
|
| Microsoft | Microsoft Office Online Server | 16.0.1 ~ 16.0.10392.20000 | - |
|
| Microsoft | Microsoft Office Web Apps Server 2013 Service Pack 1 | 15.0.1 ~ 15.0.5501.1000 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2022-41128 | 8.8 HIGH | Windows Scripting Languages Remote Code Execution Vulnerability |
| CVE-2022-41062 | 8.8 HIGH | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2022-41048 | 8.8 HIGH | Microsoft ODBC Driver Remote Code Execution Vulnerability |
| CVE-2022-41047 | 8.8 HIGH | Microsoft ODBC Driver Remote Code Execution Vulnerability |
| CVE-2022-41080 | 8.8 HIGH | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2022-41039 | 8.1 HIGH | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability |
| CVE-2022-41088 | 8.1 HIGH | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability |
| CVE-2022-37966 | 8.1 HIGH | Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability |
| CVE-2022-38023 | 8.1 HIGH | Netlogon RPC Elevation of Privilege Vulnerability |
| CVE-2022-41044 | 8.1 HIGH | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability |
| CVE-2022-41078 | 8.0 HIGH | Microsoft Exchange Server Spoofing Vulnerability |
| CVE-2022-41079 | 8.0 HIGH | Microsoft Exchange Server Spoofing Vulnerability |
| CVE-2022-41120 | 7.8 HIGH | Microsoft Windows System Monitor (Sysmon) Elevation of Privilege Vulnerability |
| CVE-2022-41119 | 7.8 HIGH | Visual Studio Remote Code Execution Vulnerability |
| CVE-2022-41095 | 7.8 HIGH | Windows Digital Media Receiver Elevation of Privilege Vulnerability |
| CVE-2022-41092 | 7.8 HIGH | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2022-41093 | 7.8 HIGH | Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability |
| CVE-2022-41101 | 7.8 HIGH | Windows Overlay Filter Elevation of Privilege Vulnerability |
| CVE-2022-41100 | 7.8 HIGH | Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability |
| CVE-2022-41107 | 7.8 HIGH | Microsoft Office Graphics Remote Code Execution Vulnerability |
Showing top 20 of 62 CVEs. View all on vendor page → →
No comments yet