QID 110445

Date Published: 2023-08-09

QID 110445: Microsoft Office Security Update for August 2023

Microsoft has released August 2023 security updates to fix multiple security vulnerabilities.

This security update contains the following:

Office Click-2-Run and Office 365 Release Notes
KB5002451
KB5002463
KB5002435
KB5002445
KB5002464
QID Detection Logic (Authenticated):
Operating System: Windows
The detection extracts the Install Path for Microsoft Office via the Windows Registry. The QID checks the file version of "graph.exe" to identify vulnerable versions of Microsoft Office. Patched Versions for Microsoft 365 Apps for enterprise, Microsoft 365 Apps for business, Office 2016 Retail (C2R), Office 2019, Office Current Channel: Version 2307 (Build 16626.20170) Monthly Enterprise Channel: Version 2306 (Build 16529.20226).
Monthly Enterprise Channel: Version 2305 (Build 16501.20286).
Semi-Annual Enterprise Channel (Preview): Version 2302 (Build 16130.20714).
Semi-Annual Enterprise Channel: Version 2302 (Build 16130.20714).
Semi-Annual Enterprise Channel: Version 2208 (Build 15601.20742).
Semi-Annual Enterprise Channel: Version 2202 (Build 14931.21078).
Office 2021 Retail: Version 2307 (Build 16626.20170).
Office 2019 Retail: Version 2307 (Build 16626.20170).
Office 2016 Retail: Version 2306 Version 2307 (Build 16626.20170).
Office LTSC 2021 Volume Licensed: Version 2108 (Build 14332.20546).
Office 2019 Volume Licensed: Version 1808 (Build 10401.20025).

Note: Office click-2-run and Office 365 installations need to be updated manually or need to be set to automatic update. There is no direct download for the patch.

Successful exploitation allows an attacker to execute code remotely.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Software Advisories
    Advisory ID Software Component Link
    Microsoft office July 2023 URL Logo msrc.microsoft.com/update-guide/