- PTA warns users of high-severity vulnerabilities in Microsoft products.
- Vulnerabilities target specific components of Microsoft Office products: Visio (CVE-2024-43505).
- Ignoring these recommendations could leave systems vulnerable to targeted cyberattacks
Attackers can exploit these security flaws to execute arbitrary code or escalate user privileges, posing serious threats to users and organizations that rely on these services.
According to the advisory, the vulnerabilities target specific components of Microsoft Office products: Visio (CVE-2024-43505), Excel (CVE-2024-43504), and SharePoint (CVE-2024-43503). In Visio, attackers can execute arbitrary code by processing specially crafted content. Excel's use-after-free vulnerability enables code execution through maliciously designed files. SharePoint allows authenticated attackers to escalate privileges by sending specially crafted requests.
The PTA classified these vulnerabilities as high severity and emphasized the significant security risks of delaying patches or system updates. These flaws allow local attackers to exploit systems lacking proper protection, potentially compromising sensitive data or granting unauthorized access across networks and platforms.
The advisory strongly urges users and organizations to regularly update all Microsoft products to reduce security risks. The PTA specifically recommends consulting the Microsoft Security Update Guide to apply relevant patches and ensure all software remains up to date with the latest security enhancements, especially in environments that heavily rely on enterprise applications.
The advisory further warned that ignoring these recommendations could leave systems vulnerable to targeted cyberattacks. It urged system administrators and IT departments to review their current security protocols and promptly apply the necessary patches to prevent exploitation of these vulnerabilities.
[embedpost slug="pta-grants-120-day-mobile-registration-to-visiting-overseas-pakistanis/"]