CVE-2023-21715CISA KEV
Microsoft Office Publisher Security Feature Bypass Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft Office Publisher contains a security feature bypass vulnerability that allows for a local, authenticated attack on a targeted system.
- Product
- Office
- Added to KEV
- 14 Feb 2023
- Federal remediation due
- 7 Mar 2023
- Known ransomware use
- Not reported