CVE-2023-36761

MEDIUM(6.5)KEVElevated Risk

Microsoft Word Information Disclosure Vulnerability

Description

CVE-2023-36761 is an information disclosure vulnerability in Microsoft Word caused by improper input validation that allows a remote attacker to extract sensitive information from the target system. By crafting a malicious Word document, an attacker can exploit this flaw to disclose data such as NTLM hashes without requiring any authentication, though user interaction is needed to open the document. CVE-2023-36761 affects Microsoft Word, Microsoft 365 Apps, Microsoft Office, and Microsoft Office Long Term Servicing Channel. CISA has confirmed active exploitation of this vulnerability in the wild and added it to the Known Exploited Vulnerabilities catalog, with an EPSS score of 7.3% placing it in the 91st percentile of exploited vulnerabilities.

KEV Information

Vendor
Microsoft
Product
Word
Date Added
September 12, 2023
Due Date
October 3, 2023
Required Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
3.6

CWEs

Affected Products

VendorProductVersion
microsoft365 apps-
microsoftoffice2019
microsoftoffice long term servicing channel2021
microsoftword2013; 2016

Multiple CVSS Assessments

Source: [email protected](Secondary)
6.5
MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Source: [email protected](Primary)
6.5
MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

References

Weakness Type

CWE-20: Improper Input Validation

CVE-2023-36761 is rooted in improper input validation within Microsoft Word's document processing functionality. The software fails to adequately validate certain inputs during document parsing, allowing a crafted document to trigger the disclosure of sensitive information such as NTLM authentication hashes to an attacker-controlled server.

Learn more: CWE-20 — Improper Input Validation

Impact Analysis

CVE-2023-36761 is remotely exploitable over the network without physical access and with low attack complexity, requiring no special conditions for successful exploitation. Privileges Required (None): no authentication is needed to craft and deliver the malicious document. User Interaction (Required): the victim must open the malicious Word document or, in some cases, merely preview it in the Windows Explorer preview pane for the vulnerability to trigger. Confidentiality (High): successful exploitation can lead to the disclosure of highly sensitive information, including NTLM hashes that can be relayed or cracked to gain unauthorized access to other systems and resources. Integrity (None): the vulnerability does not allow direct modification of data. Availability (None): exploitation does not impact system availability. With a CVSS score of 6.5 (Medium) and CISA confirmation of active exploitation, this vulnerability is particularly dangerous in environments where NTLM authentication is used, as disclosed hashes can enable lateral movement and privilege escalation.

Exploit Maturity

CISA has confirmed active exploitation of CVE-2023-36761 in the wild by adding it to the Known Exploited Vulnerabilities catalog with a remediation deadline of October 3, 2023. The EPSS score of 7.3% places this vulnerability in the 91st percentile, indicating a significant probability of exploitation activity. While no specific public exploit code is tagged in the available references, the confirmed active exploitation and the relatively straightforward attack vector of delivering a crafted Word document make this a high-priority threat. Microsoft has published a security update addressing this vulnerability.

Remediation

  1. Apply Microsoft security updates immediately: Install the patches provided by Microsoft through the Security Update Guide for CVE-2023-36761 for all affected products including Microsoft Word, Microsoft 365 Apps, Microsoft Office, and Microsoft Office Long Term Servicing Channel. CISA required remediation by October 3, 2023.
  2. Disable the Windows Explorer preview pane: As an interim mitigation, disable the preview pane in Windows Explorer to prevent automatic triggering of the vulnerability when browsing folders containing malicious Word documents. This reduces the attack surface by requiring the user to explicitly open the file.
  3. Implement email and document filtering: Deploy email gateway filtering to detect and quarantine suspicious Word documents, particularly those from external or untrusted sources. Configure Microsoft Defender for Office 365 or equivalent solutions to scan attachments for known exploitation patterns targeting input validation flaws.
  4. Monitor for NTLM hash exfiltration: Review network logs and endpoint detection telemetry for outbound SMB connections or NTLM authentication attempts to external or suspicious IP addresses, which may indicate exploitation of this vulnerability to capture NTLM hashes.
  5. Strengthen NTLM authentication posture: As a long-term hardening measure, restrict outbound NTLM authentication using group policy, implement SMB signing, and consider migrating to Kerberos-only authentication where possible to reduce the impact of NTLM hash disclosure vulnerabilities.

Technical Details

CVE-2023-36761 is classified under CWE-20 (Improper Input Validation) and manifests in Microsoft Word's document processing engine, where insufficient validation of document content allows an attacker to craft a Word file that, when opened or previewed, triggers an outbound connection that leaks NTLM authentication hashes to an attacker-controlled destination. The CVSS vector (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N) indicates that while the attack is network-delivered with low complexity and requires no privileges, user interaction is necessary, limiting the scope to scenarios where the victim opens or previews the malicious document. The scope is unchanged, meaning the impact is confined to the vulnerable Microsoft Word process and the credentials it can access, though the disclosed NTLM hashes effectively extend the blast radius to any system where those credentials are valid. The high confidentiality impact with no integrity or availability impact reflects the information disclosure nature of this vulnerability, where the primary objective is credential theft rather than direct system compromise.

Frequently Asked Questions

Is CVE-2023-36761 being actively exploited?

Yes, CVE-2023-36761 is being actively exploited in the wild. CISA has confirmed active exploitation by adding this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog with a mandatory remediation deadline of October 3, 2023. The EPSS score of 7.3% places it in the 91st percentile.

What products are affected by CVE-2023-36761?

CVE-2023-36761 affects Microsoft Word, Microsoft 365 Apps, Microsoft Office, and Microsoft Office Long Term Servicing Channel. All supported versions of these products are potentially vulnerable until the security update is applied.

How do I fix CVE-2023-36761?

Install the security updates provided by Microsoft through the Security Update Guide for CVE-2023-36761. As interim mitigations, disable the Windows Explorer preview pane to prevent automatic triggering and implement email filtering to quarantine suspicious Word documents from untrusted sources.

How severe is CVE-2023-36761?

CVE-2023-36761 has a CVSS score of 6.5 (Medium severity) with high confidentiality impact, reflecting its ability to disclose sensitive information such as NTLM hashes. While rated as medium severity, the real-world risk is elevated due to confirmed active exploitation and the potential for disclosed credentials to enable lateral movement in enterprise environments.

CVSS Score

6.5
MEDIUM(6.5)

EPSS Score

EPSS Score18.96%
EPSS Percentile97.1%

Dates

PublishedSeptember 12, 2023
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.