LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-21715: Microsoft Office Publisher Security Feature Bypass Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 14, 2023
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 7, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-21715 to its Known Exploited Vulnerabilities catalog on Feb 14, 2023, with a federal patch deadline of Mar 7, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Office Publisher contains a security feature bypass vulnerability that allows for a local, authenticated attack on a targeted system.

CVE-2023-21715 is a security feature bypass vulnerability in Microsoft Office Publisher. It allows a local, authenticated attacker to bypass a security control on a targeted system. For IT and security teams, this matters because Publisher is part of the Microsoft Office suite commonly installed on endpoints; a successful bypass can weaken protections that normally limit what an authenticated user or process can do, increasing the chance of further compromise on that host.

Public detail is limited to the CISA summary and the CWE classification. Confirm exact product editions, build numbers, and impact against the official Microsoft advisory before treating any system as unaffected.

How it works

The underlying weakness is CWE-863 (Incorrect Authorization). In this class of flaw, a security feature that should enforce authorization or other protective checks fails to do so correctly under certain conditions. An attacker who already has local authenticated access to a system running the vulnerable Publisher component can abuse the bypass to circumvent the intended control.

No public exploit mechanics, privilege-escalation path, or remote-vector details are provided in the given facts. Treat the attack as local and authenticated only, and do not assume remote code execution or unauthenticated access unless the vendor advisory explicitly states otherwise. The practical result is that a security boundary Publisher is expected to maintain can be defeated, potentially allowing actions the feature was designed to block.

Am I affected? How to find it in your systems

Microsoft Office Publisher typically runs on Windows endpoints used by knowledge workers, marketing teams, and anyone who creates or opens Publisher (.pub) documents. It may be installed as part of a full Office suite or as a standalone component.

If your inventory tooling cannot distinguish Publisher from other Office apps, treat any Office installation as potentially in scope until you confirm the exact build against the vendor advisory.

How to remediate

Patch first. Apply the Microsoft updates that address CVE-2023-21715 exactly as directed in the vendor advisory and the CISA required action (“Apply updates per vendor instructions”). Use your normal patch-deployment pipeline (WSUS, Intune, SCCM, or manual installation) and verify successful installation via build-number checks.

If you can't patch immediately

Until the vendor update can be deployed, reduce risk with compensating controls appropriate to a local authenticated security-feature bypass:

These measures lower likelihood and impact but do not replace the official update. Schedule the patch as soon as operationally possible.

If your data may have been exposed

Actively exploited vulnerabilities can lead to broader compromise of the host and any data accessible to the authenticated user. Known ransomware use of this CVE is not documented in the provided facts. If you suspect exploitation, isolate the endpoint, preserve forensic evidence, and follow your incident-response process. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data to see whether credentials or personal information have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Office
WeaknessCWE-863
Added to CISA KEVFeb 14, 2023
Federal patch deadlineMar 7, 2023
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities