Good afternoon,We are seeing quite a few Office related CVEs and would like to investigate them further to check if they are a false positive.The one CVE im going to investigate first is CVE-2023-33150All of my clients are running the Wazuh agent version 4.9.0Wazuh Manager is also 4.9.0I have recently deployed Office 2021 LTSC Build number = 14332.20771 Version = 2108
The Microsoft article for this CVE shows there is an update for Office 2021 LTSChttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-33150The update notes for the Office 2021 LTSChttps://learn.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updatesThis is for the patch that was released on September the 10th which is the exact same version and build number of my deployed Office.Is this a false positive?Are there any steps I can take to resolve this logged CVE?
I'm also seeing the following CVE's related to the above Office 2021 packageCVE-1999-0794CVE-2006-1311CVE-2021-42293CVE-2021-42295CVE-2021-42296CVE-2021-43255CVE-2021-43256CVE-2021-43875CVE-2022-21840CVE-2022-21841CVE-2022-24461CVE-2022-24462CVE-2022-24473CVE-2022-24509CVE-2022-24510CVE-2022-24511CVE-2022-26901CVE-2022-29107CVE-2022-29109CVE-2022-41060CVE-2022-41061CVE-2022-41063CVE-2022-41103CVE-2022-41104CVE-2022-41105.... and many more! (Shall i continue posting the CVE IDs?The Package name is showing as "Microsoft Office LTSC Professional Plus 2021 - en-us"and package.version = "16.0.14332.20771"Thanks!
The Blessed Edward Bamber Catholic Multi Academy Trust is a company limited by guarantee and an exempt charity registered in England and Wales under company number 9111449, and registered office 14-17 Metro House, Metropolitan Drive, FY3 9LT.
St Mary’s Catholic Academy is a business name of the company.
A copy of the our data protection policy can be found on the trust website, www.bebcmat.co.uk