📣 Send us your press release
Site updates every 15 minutes
Technology

Picus Security Analyzes Microsoft Word Remote Code Execution Vulnerability CVE-2023-21716

Cybersecurity firm Picus Security has released a detailed analysis of the critical Microsoft Word vulnerability CVE-2023-21716. The flaw allows for remote code execution and carries a CVSS score of 9.8.

26 July 2026
Picus Security Analyzes Microsoft Word Remote Code Execution Vulnerability CVE-2023-21716
Image is an AI-generated illustration

Cybersecurity firm Picus Security has published a thorough examination of the CVE-2023-21716 vulnerability affecting Microsoft Word. This critical flaw, rated with a CVSS score of 9.8, allows for remote code execution if exploited.

The vulnerability resides within Microsoft Office's RTF parser. When exploited, it enables attackers to execute arbitrary commands with the privileges of the victim user. Exploitation can occur simply by previewing a malicious RTF file, without the user needing to open it fully. Microsoft addressed this issue in its February 2023 security updates.

Picus Security has incorporated simulations of CVE-2023-21716 exploitation attempts into its Threat Library. The analysis provides technical details on how the vulnerability functions, including a proof-of-concept example. The company strongly advises users to update their software promptly.

The vulnerability impacts multiple versions of Microsoft Office, SharePoint, and Microsoft 365 apps. Picus Security offers solutions for organizations to test and enhance their defenses against such threats.

Original source: picussecurity.com