## Title: Microsoft Word Remote Code Execution Vulnerability## Author: nu11secur1ty## Date: 04.14.2023## Vendor: https://www.microsoft.com/## Software:https://www.microsoft.com/en-us/microsoft-365/word?activetab=tabs%3afaqheaderregion3## Reference:https://www.crowdstrike.com/cybersecurity-101/remote-code-execution-rce/## CVE-2023-28311## Description:The attack itself is carried out locally by a user with authentication tothe targeted system. An attacker could exploit the vulnerability byconvincing a victim, through social engineering, to download and open aspecially crafted file from a website which
Microsoft has resolved 80 new CVEs in addition to four previously released CVEs, bringing the number of security issues addressed in this month's Patch Tuesday to 84 including two zero-days.