← Vulnerability feed

Vulnerability record · CVE-2023-21715 · published 14 February 2023

CVE-2023-21715: Microsoft Publisher security feature bypass via incorrect authorization

Microsoft · 365 Apps

CVE-2023-21715 is a security feature bypass in Microsoft Publisher, caused by incorrect authorization (CWE-863). A local attacker with low privileges who convinces a user to open a crafted file can evade the protections Publisher relies on, which matters because the flaw was exploited in the wild and added to CISA's KEV catalog.

7.3 CVSS 3.1 High CISA KEV since 14 Feb 2023 EPSS 12% · top 4.0% CWE-863 · Incorrect authorization
7.3CVSS 3.1 base score
12%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
19 Aug 2026Last modified by NVD

Description

Microsoft Publisher Security Feature Bypass Vulnerability

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityThe flaw is confirmed exploited in the wild and listed in CISA KEV, but it requires local access and user interaction, which limits mass exploitation.

What it is

CVE-2023-21715 is a security feature bypass in Microsoft Publisher, caused by incorrect authorization (CWE-863). A local attacker with low privileges who convinces a user to open a crafted file can evade the protections Publisher relies on, which matters because the flaw was exploited in the wild and added to CISA's KEV catalog.

Impact

An attacker gains the ability to bypass Publisher's security controls, enabling follow-on actions such as loading malicious content or executing code that the feature was meant to block. The CVSS vector rates high confidentiality, integrity and availability impact.

Attack surface

The vector is local (AV:L) with low privileges (PR:L) and required user interaction (UI:R), so the attacker must already have a foothold on the host and persuade the victim to open a malicious Publisher document. No remote or unauthenticated path is described.

Exploitation

CISA added this CVE to the Known Exploited Vulnerabilities catalog on 2023-02-14 with a remediation due date of 2023-03-07, confirming active exploitation; EPSS gives a 30-day probability of about 12 percent (95.9th percentile). No ransomware campaign use is documented.

What to do

  • Apply the Microsoft update for CVE-2023-21715 per the MSRC advisory as the first action.
  • Block or restrict opening of untrusted Publisher (.pub) files, especially from email and downloads.
  • Enforce least privilege so users do not run with rights that widen the impact of a local bypass.
  • Use attack surface reduction and Office hardening controls to limit content that Publisher can load.
  • Track KEV remediation deadlines and confirm patched status across all Office installations.

Detection

  • Monitor process creation for Publisher (MSPUB.EXE) spawning child processes such as script hosts or Office applications.
  • Alert on Publisher documents opened from email attachments, downloads or temporary internet directories.
  • Review endpoint telemetry for anomalous file or registry writes originating from Publisher processes.
  • Audit hosts still running unpatched Office builds against the MSRC fixed version list.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-21715 to the Known Exploited Vulnerabilities catalog on 14 February 2023 as "Microsoft Office Publisher Security Feature Bypass Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 7 March 2023.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-21715 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-21413Microsoft Outlook improper input validation remote code executionCVE-2024-21413 is a critical remote code execution flaw in Microsoft Outlook caused by improper input validation, tracked publicly as the MonikerLink…KEVEPSS 95%analysed9.8CVE-2023-23397Microsoft Outlook improper input validation privilege escalationCVE-2023-23397 is a critical elevation of privilege flaw in Microsoft Outlook caused by improper input validation and an authentication bypass by cap…KEVEPSS 97%analysed8.8CVE-2024-38189Microsoft Project Remote Code Execution via Improper Input ValidationMicrosoft Project and related Office products contain a remote code execution flaw rooted in improper input validation. An attacker can trigger code …KEVEPSS 8.2%analysed8.8CVE-2023-35311Microsoft Outlook security feature bypass via TOCTOU race conditionCVE-2023-35311 is a security feature bypass in Microsoft Outlook caused by a time-of-check time-of-use (TOCTOU) race condition (CWE-367). It affects …KEVEPSS 16%analysed7.8CVE-2026-21514Microsoft Word security feature bypass via untrusted inputMicrosoft Word relies on untrusted inputs when making a security decision, allowing an attacker to bypass a security feature. The flaw affects Micros…KEVEPSS 1.5%analysed7.8CVE-2026-21509Microsoft Office untrusted input security feature bypassMicrosoft Office relies on untrusted inputs when making a security decision, letting an unauthorized attacker bypass a security feature locally. The …KEVEPSS 73%analysed7.8CVE-2021-42292Microsoft Excel security feature bypass via crafted fileCVE-2021-42292 is a security feature bypass in Microsoft Excel and related Office products. The record gives only a one-line description, so the exac…KEVEPSS 43%analysed7.8CVE-2021-38646Microsoft Office Access Connectivity Engine remote code executionThe Microsoft Office Access Connectivity Engine contains a remote code execution flaw. The record gives no root-cause detail beyond the CWE being mar…KEVEPSS 8.0%analysed

Source: NIST National Vulnerability Database (record CVE-2023-21715), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.