漏洞描述 Microsoft Publisher是微软公司发行的桌面出版应用软件。 Microsoft Publisher处理特制.pub文件的方式中存在远程代码执行漏洞。攻击者可利用该漏洞以当前用户权限执行任意代码。
相关漏洞推荐 POC CVE-2025-49706: Microsoft SharePoint Server - Authentication Bypass (CVE-2025-53770)Microsoft SharePoint Server反序列化漏洞允许远程代码执行 (CVE-2025-61882)Oracle Concurrent Processing BI Publisher Integration 远程接管漏洞 POC CVE-2019-0604: Microsoft SharePoint - Remote Code Execution POC CVE-2020-0646: Microsoft .NET Framework - Remote Code Execution POC CVE-2000-0114: Microsoft FrontPage Extensions - Information Disclosure POC CVE-2008-1547: Microsoft OWA Exchange Server 2003 - 'redir.asp' Open Redirection POC CVE-2015-1635: Microsoft Windows 'HTTP.sys' - Remote Code Execution POC CVE-2019-2616: Oracle Business Intelligence/XML Publisher - XML External Entity Injection POC CVE-2019-2767: Oracle Business Intelligence Publisher - XML External Entity Injection POC CVE-2020-0618: Microsoft SQL Server Reporting Services - Remote Code Execution POC CVE-2020-16952: Microsoft SharePoint - Remote Code Execution POC CVE-2021-24666: WordPress Podlove Podcast Publisher <3.5.6 - SQL Injection