Microsoft 365 apps have a lot of new security vulnerabilities - here's what we know

Microsoft 365
(Image credit: Microsoft)

Cybersecurity researchers from Zscaler have discovered more than a hundred vulnerabilities in Microsoft 365 that were introduced with the addition of SketchUp into the cloud productivity suite. 

To make matters worse, they claim to have managed to bypass the patches Microsoft released to address these flaws.

Zscaler’s ThreatLabz team has published a report claiming to have found 117 vulnerabilities in Microsoft 365 apps, all due to the productivity suite supporting SketchUp 3D files - SKP.

Bypassed solutions

In essence, the program allows users to add 3D models to Microsoft documents and was first introduced in August 2000. Last year, it was integrated into Microsoft 365’s Office 3D component.

By reverse engineering the Office 3D components, the researchers discovered that Microsoft used multiple SketchUp C APIs to allow the programs to parse an SKP file. That led them first to the discovery of 20 flaws, and then to another 97 flaws. Most are heap buffer overflow, out-of-bounds write, or stack buffer overflow vulnerabilities.

Microsoft placed all of them under a “remote code execution” (RCE) umbrella and grouped them into three CVEs: CVEs: CVE-2023-28285, CVE-2023-29344, and CVE-2023-33146. All three are labeled “high severity” with a severity score of 7.8. 

Speaking to TechTarget, Zscaler’s senior principal security researcher Kai Lu said the company found no evidence of the flaws being exploited in the wild. He added that could change at any time. 

"There is a possibility that a skilled threat actor can discover and weaponize the same (or similar) vulnerabilities," Lu told the publication. "The decision to temporarily disable support for SketchUp will prevent exploitation for versions that have been patched and limit the potential impact."

Microsoft disabled the support for SketchUp, SC Media added, because the researchers managed to work around the patches it published.

“Microsoft created a patch to address the vulnerabilities that ThreatLabz was able to bypass,” the ZScaler blog reads, without going into further detail. The company did say that the report was just the first in a series, so we can expect more details in the coming days. 

Microsoft, on the other hand, told TechTarget that its customers “have been protected since June when this feature was temporarily disabled" and added that the customers should view SketchUp’s status on its dedicated page.

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
The best free firewall
Microsoft fixes Power Pages security flaw, tells users to be on their guard
A person at a laptop with a cybersecure lock symbol floating above it.
Parallels Desktop has some worrying security flaws for Mac users
A person at a laptop with a cybersecure lock symbol floating above it.
A worrying security flaw could have left Microsoft SharePoint users open to attack
A hacker wearing a hoodie sitting at a computer, his face hidden.
Microsoft patches three worrying security flaws in its latest critical update, so update now
Representational image of a cybercriminal
Microsoft just patched a host of worrying security issues, so update now
Flag of the People's Republic of China overlaid with a technological network of wires and circuits.
One of the biggest flaws exploited by Salt Typhoon hackers has had a patch available for years
Latest in Security
Lock on Laptop Screen
Data breach at Pennsylvania education union potentially exposes 500,000 victims
An American flag flying outside the US Capitol building against a blue sky
Five Eyes "cannot replace US intel in Ukraine", claims former US Cyber Command Chief
Pirate skull cyber attack digital technology flag cyber on on computer CPU in background. Darknet and cybercrime banner cyberattack and espionage concept illustration.
Criminals are using a virtual hard disk image file to host and distribute dangerous malware
WordPress on a laptop
Over 20,000 WordPress sites hit by damaging malware campaign
Trojan
WhatsApp patches security flaw which let hackers install spyware
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
A worrying Apple Password App vulnerability reportedly left users exposed for months
Latest in News
Lock on Laptop Screen
Data breach at Pennsylvania education union potentially exposes 500,000 victims
Boston Dynamics all electric Altas
This robot can do a cartwheel better than me and now I'm freaking out – but in a good way
A image of Saros character Arjun
Housemarque’s boss is surprisingly positive about Sony’s acquisition – and it’s good news for Saros
Oura Ring 4
One of Apple's top health execs is ditching the company for Oura, and I've never been more convinced smart rings are the future
Living room with Microsoft Xbox Series X (L) and Sony PlayStation 5 home video game consoles alongside a television and soundbar, taken on November 3, 2020.
The PS5 is currently selling faster than the PS4 did in the US, but I'm surprised to discover that the Xbox Series X and S are trailing behind Xbox One
Nvidia logo
Nvidia RTX 5060 Ti could be delayed to mid-April and RTX 5060 to mid-May – is AMD starting to look like a clear winner in the battle of Blackwell vs RDNA 4 GPUs?