QID 110454

Date Published: 2023-12-13

QID 110454: Microsoft Outlook Information Disclosure and Mac Spoofing Vulnerability for December 2023

Microsoft has released December 2023 security updates for outlook to fix an Information Disclosure Vulnerability.

This security update contains the following:

CVE-2023-35636: Information Disclosure Vulnerability
KB5002520
Office Click-2-Run and Office 365 Release Notes

CVE-2023-35619: Mac Spoofing Vulnerability
Microsoft Office LTSC for Mac 2021

QID Detection Logic (Authenticated):
Operating System: Windows
The detection extracts the Install Path for Microsoft Office via the Windows Registry. The QID checks the file version of "graph.exe" to identify vulnerable versions of Microsoft Office.
Patched Versions for Microsoft 365 (C2R) are:
TBD Operating System: MacOS
This authenticated QID checks the file versions from the Microsoft advisory with the versions on affected outlook applications.

Note: Office click-2-run and Office 365 installations need to be updated manually or need to be set to automatic update. There is no direct download for the patch.

Successful exploitation will lead to Mac Spoofing and/or Information Disclosure Vulnerability.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution
    Refer to Microsoft Security Guide, and KB5002520
    for more details pertaining to this vulnerability.

    CVEs related to QID 110454

    Software Advisories
    Advisory ID Software Component Link
    Microsoft Outlook December 2023 URL Logo msrc.microsoft.com/update-guide/