Vulnerability record · CVE-2023-21715 · published 14 February 2023
CVE-2023-21715: Microsoft Publisher security feature bypass via incorrect authorization
Microsoft · 365 Apps
CVE-2023-21715 is a security feature bypass in Microsoft Publisher, caused by incorrect authorization (CWE-863). A local attacker with low privileges who convinces a user to open a crafted file can evade the protections Publisher relies on, which matters because the flaw was exploited in the wild and added to CISA's KEV catalog.
Description
Microsoft Publisher Security Feature Bypass Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw is confirmed exploited in the wild and listed in CISA KEV, but it requires local access and user interaction, which limits mass exploitation.
What it is
CVE-2023-21715 is a security feature bypass in Microsoft Publisher, caused by incorrect authorization (CWE-863). A local attacker with low privileges who convinces a user to open a crafted file can evade the protections Publisher relies on, which matters because the flaw was exploited in the wild and added to CISA's KEV catalog.
Impact
An attacker gains the ability to bypass Publisher's security controls, enabling follow-on actions such as loading malicious content or executing code that the feature was meant to block. The CVSS vector rates high confidentiality, integrity and availability impact.
Attack surface
The vector is local (AV:L) with low privileges (PR:L) and required user interaction (UI:R), so the attacker must already have a foothold on the host and persuade the victim to open a malicious Publisher document. No remote or unauthenticated path is described.
Exploitation
CISA added this CVE to the Known Exploited Vulnerabilities catalog on 2023-02-14 with a remediation due date of 2023-03-07, confirming active exploitation; EPSS gives a 30-day probability of about 12 percent (95.9th percentile). No ransomware campaign use is documented.
What to do
- Apply the Microsoft update for CVE-2023-21715 per the MSRC advisory as the first action.
- Block or restrict opening of untrusted Publisher (.pub) files, especially from email and downloads.
- Enforce least privilege so users do not run with rights that widen the impact of a local bypass.
- Use attack surface reduction and Office hardening controls to limit content that Publisher can load.
- Track KEV remediation deadlines and confirm patched status across all Office installations.
Detection
- Monitor process creation for Publisher (MSPUB.EXE) spawning child processes such as script hosts or Office applications.
- Alert on Publisher documents opened from email attachments, downloads or temporary internet directories.
- Review endpoint telemetry for anomalous file or registry writes originating from Publisher processes.
- Audit hosts still running unpatched Office builds against the MSRC fixed version list.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-21715 to the Known Exploited Vulnerabilities catalog on 14 February 2023 as "Microsoft Office Publisher Security Feature Bypass Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 7 March 2023.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21715 | PatchVendor Advisory |
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21715 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-21715 | US Government Resource |
Track CVE-2023-21715 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-21715), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.