QID 110453

Date Published: 2023-12-13

QID 110453: Microsoft Office Security Update for December 2023

Microsoft has released December 2023 security updates to fix multiple security vulnerabilities.

This security update contains the following:
Office Click-2-Run and Office 365 Release Notes
KB5002520

QID Detection Logic (Authenticated):
Operating System: Windows
The detection extracts the Install Path for Microsoft Office via the Windows Registry. The QID checks the file version of "graph.exe" to identify vulnerable versions of Microsoft Office.
Patched Versions for Microsoft 365 (C2R) are:
TBD Note: Office click-2-run and Office 365 installations need to be updated manually or need to be set to automatic update. There is no direct download for the patch.

Vulnerable products may be prone to Information Disclosure Vulnerability.

  • CVSS V3 rated as Medium - 5.5 severity.
  • CVSS V2 rated as Medium - 4.9 severity.
  • Solution
    Customers are advised to refer to these KB Article(s):
    KB5002520 for more information regarding this vulnerability.

    Vendor References

    CVEs related to QID 110453

    Software Advisories
    Advisory ID Software Component Link
    Microsoft office December 2023 URL Logo msrc.microsoft.com/update-guide/