← Vulnerability feed

Vulnerability record · CVE-2023-21716 · published 14 February 2023

CVE-2023-21716: Microsoft Word integer overflow remote code execution

Microsoft · Office

CVE-2023-21716 is a critical remote code execution flaw in Microsoft Word, tied to an integer overflow (CWE-190). The record gives only a one-line description, so the exact parsing path and affected code are not detailed, but the CVSS vector indicates a network-reachable, no-authentication, no-interaction bug with full confidentiality, integrity and availability impact.

9.8 CVSS 3.1 Critical EPSS 85% · top 0.3% CWE-190 · Integer overflow
9.8CVSS 3.1 base score
85%EPSS exploitation probability, 30 days
NoNot in CISA KEV
8Affected product versions listed by NVD
2References
19 Aug 2026Last modified by NVD

Description

Microsoft Word Remote Code Execution Vulnerability

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with network reachability, no authentication and no user interaction, combined with a 99.6th percentile EPSS score, makes this an urgent patch target despite the thin description.

What it is

CVE-2023-21716 is a critical remote code execution flaw in Microsoft Word, tied to an integer overflow (CWE-190). The record gives only a one-line description, so the exact parsing path and affected code are not detailed, but the CVSS vector indicates a network-reachable, no-authentication, no-interaction bug with full confidentiality, integrity and availability impact.

Impact

An attacker who can get a crafted document processed gains code execution in the context of the Word or affected Office/SharePoint service process, which can lead to full host compromise. Because the vector shows no privileges or user interaction required, the impact is not limited to a single victim opening a file.

Attack surface

Reachable over the network (AV:N) with no authentication (PR:N) and no user interaction (UI:N) per the CVSS vector, so a crafted document or request reaching Word, Office Online Server, Office Web Apps or SharePoint is the likely path. The record does not specify the exact entry point, so treat any document-processing endpoint as exposed.

Exploitation

Not listed in CISA KEV and no ransomware use is documented, but EPSS is very high at 0.823 (99.6th percentile), indicating strong predicted exploitation pressure. The only references are Microsoft patch advisories, so no public exploit or in-the-wild confirmation is stated in this record.

What to do

  • Apply the Microsoft update for CVE-2023-21716 to Word, Office, Office Online Server, Office Web Apps and SharePoint as the first action.
  • Prioritize internet-facing and document-processing services (Office Online Server, Office Web Apps, SharePoint) for patching ahead of end-user desktops.
  • Block or sandbox untrusted documents at mail and web gateways, and disable automatic document preview/rendering where it is not needed.
  • Run Office and SharePoint service accounts with least privilege and enable Protected View and ASR rules for Office child processes.
  • Monitor Microsoft advisories for revised affected-version lists, since this record does not enumerate them.

Detection

  • Hunt for Word, Office Online Server, Office Web Apps or SharePoint processes spawning unexpected child processes such as cmd.exe, powershell.exe or wscript.exe.
  • Alert on crashes or abnormal terminations of Word/Office document-processing services that correlate with recently received documents.
  • Review gateway and SharePoint logs for documents from untrusted sources hitting preview or conversion pipelines, and flag repeated failures against the same sender or file.
  • Track EPSS and vendor advisory updates for this CVE and re-scan exposed document-processing endpoints for missing patches.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-21716 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-21413Microsoft Outlook improper input validation remote code executionCVE-2024-21413 is a critical remote code execution flaw in Microsoft Outlook caused by improper input validation, tracked publicly as the MonikerLink…KEVEPSS 95%analysed9.8CVE-2023-23397Microsoft Outlook improper input validation privilege escalationCVE-2023-23397 is a critical elevation of privilege flaw in Microsoft Outlook caused by improper input validation and an authentication bypass by cap…KEVEPSS 97%analysed9.8CVE-2019-0604Microsoft SharePoint application package markup validation RCEMicrosoft SharePoint fails to validate the source markup of an application package, allowing crafted packages to execute code on the server. This is …KEVEPSS 100%analysed8.8CVE-2024-38189Microsoft Project Remote Code Execution via Improper Input ValidationMicrosoft Project and related Office products contain a remote code execution flaw rooted in improper input validation. An attacker can trigger code …KEVEPSS 8.2%analysed8.8CVE-2023-35311Microsoft Outlook security feature bypass via TOCTOU race conditionCVE-2023-35311 is a security feature bypass in Microsoft Outlook caused by a time-of-check time-of-use (TOCTOU) race condition (CWE-367). It affects …KEVEPSS 16%analysed8.8CVE-2019-1297Microsoft Excel memory handling flaw allows remote code executionCVE-2019-1297 is a remote code execution vulnerability in Microsoft Excel caused by improper handling of objects in memory. An attacker who convinces…KEVEPSS 22%analysed8.8CVE-2019-0541Microsoft MSHTML engine input validation flaw allows remote code executionThe MSHTML engine in Microsoft Office, Internet Explorer and related viewers fails to properly validate input, allowing remote code execution. Becaus…KEVEPSS 53%analysed8.8CVE-2018-0798Microsoft Office Equation Editor memory corruption RCEEquation Editor in Microsoft Office 2007 through 2016 mishandles objects in memory, producing an out-of-bounds write (CWE-787) that can be turned int…KEVEPSS 95%analysed

Source: NIST National Vulnerability Database (record CVE-2023-21716), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.