漏洞信息
# Microsoft Office 远程代码执行漏洞
## 概述
存在一个安全漏洞,可能导致在使用FBX文件时远程代码执行。为解决此问题,已在Word、Excel、PowerPoint和Outlook(Windows和Mac版)中禁用了插入FBX文件的功能。
## 影响版本
- Office 2019
- Office 2021
- Office LTSC for Mac 2021
- Microsoft 365
## 细节
- 从2024年1月9日的安全更新开始实施此更改。
- 2024年2月13日起,3D Viewer中的FBX文件插入功能也被禁用。
- 之前已插入的FBX文件的3D模型将继续正常工作,除非插入时选择了“链接到文件”选项。
## 影响
- 所有受影响版本的Office产品将不再支持插入FBX文件的功能,以防止潜在的远程代码执行风险。
提示
尽管我们采用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。
神龙会尽力确保数据准确,但也请结合实际情况进行甄别与判断。
神龙祝您一切顺利!
漏洞标题
Microsoft Office Remote Code Execution Vulnerability
漏洞描述信息
A security vulnerability exists in FBX that could lead to remote code execution. To mitigate this vulnerability, the ability to insert FBX files has been disabled in Word, Excel, PowerPoint and Outlook for Windows and Mac. Versions of Office that had this feature enabled will no longer have access to it. This includes Office 2019, Office 2021, Office LTSC for Mac 2021, and Microsoft 365. As of February 13, 2024, the ability to insert FBX files has also been disabled in 3D Viewer.
3D models in Office documents that were previously inserted from a FBX file will continue to work as expected unless the Link to File option was chosen at insert time.
This change is effective as of the January 9, 2024 security update.
CVSS信息
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
漏洞类别
堆缓冲区溢出
漏洞标题
Microsoft Office 安全漏洞
漏洞描述信息
Microsoft Office是美国微软(Microsoft)公司的一款办公软件套件产品。该产品常用组件包括Word、Excel、Access、Powerpoint、FrontPage等。 Microsoft Office存在安全漏洞。攻击者利用该漏洞可以远程执行代码。以下产品和版本受到影响:Microsoft Office 2019 for 32-bit editions,Microsoft Office 2019 for 64-bit editions,Microsoft 365 Apps for
CVSS信息
N/A
漏洞类别
其他