> Source: [sk181248](https://support.checkpoint.com/results/sk/sk181248)

# sk181248 -  Check Point Response to CVE-2023-36884: Office and Windows HTML Remote Code Execution Vulnerability

| Property | Value |
|----------|-------|
| Solution ID | sk181248 |
| Date Created | 2023-07-14 |
| Last Modified | 2023-07-16 |
| Technical Level | General |
| Products | Security Gateway, Endpoint Security |
| Versions | R82.10, R82, R81.20, Cloud, R82.20, R82.10, R82, R81.20 |
| OS | Windows |

## Symptoms

- The information below is from the [**official Microsoft release**](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36884) regarding CVE-2023-36884:  

Microsoft is investigating reports of a series of remote code execution vulnerabilities impacting Windows and Office products. Microsoft is aware of targeted attacks that attempt to exploit these vulnerabilities by using specially-crafted Microsoft Office documents.  

An attacker could create a specially crafted Microsoft Office document that enables them to perform remote code execution in the context of the victim. However, an attacker would have to convince the victim to open the malicious file.  

Upon completion of this investigation, Microsoft will take the appropriate action to help protect our customers. This might include providing a security update through our monthly release process or providing an out-of-cycle security update, depending on customer needs.

<br />

## Cause

Microsoft is investigating this issue.

<br />

## Solution

Check Point Threat Emulation detects and prevents CVE-2023-36884 exploit with this protection: Technique.Win.OleEmbed.la.A.  

Threat Cloud covers all other related IOCs.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
