Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
CVE-2023-36884

How to Fix CVE-2023-36884: Office and Windows HTML Remote Code Execution Vulnerability

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

CVE-2023-36884 was a real, exploited 2023 vulnerability, but the correct fix in 2026 is to install all applicable Windows and Microsoft Office security updates—not to rely on the old registry workaround. Microsoft initially described targeted attacks using specially crafted Office documents. Later records classified the issue as a Windows Search Security Feature Bypass Vulnerability, so current applicability must be checked against Microsoft’s supported-product guidance.

What CVE-2023-36884 was

CVE-2023-36884 was publicly disclosed in July 2023 as the Microsoft Office and Windows HTML Remote Code Execution Vulnerability. Microsoft reported targeted exploitation in which an attacker used a specially crafted Office document and persuaded a victim to open it. Successful exploitation could allow code to run in the victim’s security context. The original description and disclosure timeline are recorded by the National Vulnerability Database and its July 2023 change record.

“Zero-day” refers to the period when exploitation was occurring before a complete vendor fix was broadly available. It does not mean the vulnerability remains permanently unpatched, and it did not mean every Office installation was automatically compromised or that exploitation was zero-click.

Microsoft associated the campaign with Storm-0978; threat-actor naming and aliases vary by reporting organization. Microsoft’s reference is https://aka.ms/Storm-0978. CVE-2023-36884 was also included in CISA’s Known Exploited Vulnerabilities catalog, with a federal remediation deadline of August 29, 2023.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why the name changed

On August 8, 2023, the NVD record was revised to call CVE-2023-36884 a Windows Search Security Feature Bypass Vulnerability and to show the later vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N. The revised record is available at this NVD change record. Different tools may therefore display the original Office/Windows HTML RCE wording or the later Windows Search name. They refer to the same CVE, but the names describe different stages of its public classification.

Who should check their systems

Do not rely on a static 2023 “all affected versions” list. Product support and servicing branches change. Use Microsoft’s live CVE-2023-36884 Security Update Guide entry and the Microsoft Security Update Guide to determine applicability for the exact product and build.

  • Supported Windows client editions and Windows Server installations.
  • Microsoft 365 Apps and perpetual Office installations that process the relevant document or protocol behavior.
  • Devices missing current cumulative, monthly, or Microsoft 365 application updates.
  • Endpoints managed through Intune, Configuration Manager, Windows Update for Business, or another patch platform.
  • Servers running Office components, document-processing workflows, or interactive administrative sessions.

A computer without Office is not automatically exempt: the later classification involved a Windows component. Conversely, “Microsoft 365” does not guarantee that a device is current; update channels, deferred servicing, policy restrictions, disconnected devices, and failed installations can leave builds behind.

The recommended fix

  1. Confirm support status. Record the Windows edition, build, architecture, Office edition, and Microsoft 365 Apps update channel.
  2. Install Windows security updates. Use your approved update ring or management platform and follow the applicable products listed by Microsoft.
  3. Update Office. For Microsoft 365 Apps, verify the installed build and update-channel compliance. For perpetual Office, install the applicable security updates for that edition.
  4. Confirm installation. Check the installed KB or resulting Windows build, Office version, and deployment-platform compliance rather than relying only on an “up to date” banner.
  5. Restart when required. Reboot Windows and close and reopen all Office applications after updates or policy changes.
  6. Review telemetry. Look for suspicious Office child processes, unusual outbound connections, malicious documents, and endpoint alerts.

Patching corrects the vulnerable condition. Email filtering, endpoint detection, and least privilege reduce risk or improve detection, but none replaces the security update.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Sale
Dell Latitude 5420 14" FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
  • 256 GB SSD of storage.
  • Multitasking is easy with 16GB of RAM
  • Equipped with a blazing fast Core i5 2.00 GHz processor.

The historical registry mitigation

During the 2023 response, Microsoft guidance used the FEATURE_BLOCK_CROSS_PROTOCOL_FILE_NAVIGATION policy under:

HKLMSoftwarePoliciesMicrosoftInternet ExplorerMainFeatureControlFEATURE_BLOCK_CROSS_PROTOCOL_FILE_NAVIGATION

Commonly documented executable values included excel.exe, graph.exe, msaccess.exe, mspub.exe, powerpnt.exe, winword.exe, visio.exe, and outlook.exe. A representative command was:

reg add "HKLMSoftwarePoliciesMicrosoftInternet ExplorerMainFeatureControlFEATURE_BLOCK_CROSS_PROTOCOL_FILE_NAVIGATION" /v "excel.exe" /t REG_DWORD /d 1 /f

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3

This is mitigation, not patching. Use it only where Microsoft’s current guidance explicitly supports it or while patch deployment is incomplete. Confirm the exact executable list in the Microsoft advisory, account for 32-bit Office on 64-bit Windows, and deploy through Group Policy or configuration management where possible. The setting can disrupt legitimate cross-protocol navigation, so document its owner, scope, business impact, review date, and removal plan.

How to verify remediation

Verify updates

  • Confirm the applicable Windows KB or build is installed.
  • Confirm the Office or Microsoft 365 Apps build and update channel.
  • Check successful compliance in Intune, Configuration Manager, or the organization’s patch platform.

Verify a deployed mitigation

Run PowerShell as an administrator:

Get-ItemProperty -Path "HKLM:SoftwarePoliciesMicrosoftInternet ExplorerMainFeatureControlFEATURE_BLOCK_CROSS_PROTOCOL_FILE_NAVIGATION"

  • Expected executable values are present and set to 1.
  • The policy exists in the registry view read by the affected Office architecture.
  • Policy refresh, reboot, and Office restart have occurred.
  • No domain, user, or application policy is overwriting the setting.

This registry check proves only that a mitigation is configured; it does not prove that the underlying vulnerability is patched.

If exploitation may have occurred

  1. Isolate the endpoint according to your incident-response procedure.
  2. Preserve the suspicious document, Office process tree, endpoint alerts, and relevant network telemetry.
  3. Investigate Office child processes, persistence, and unusual outbound connections.
  4. Reset credentials if compromise or credential exposure is possible.
  5. Escalate to the organization’s incident-response team and preserve evidence before reimaging.

Patch, mitigation, and detection compared

Control What it does Limitation
Microsoft security update Corrects the vulnerable condition for supported products Requires testing, deployment, and verification
Registry mitigation Blocks the documented behavior during an emergency Not equivalent to a patch and may affect legitimate navigation
Email filtering Reduces delivery of malicious documents Does not cover local files or alternate delivery paths
Endpoint detection and response Helps identify exploitation and post-exploitation activity Detection is not prevention or remediation
Least privilege Limits damage if code executes Does not remove exploitation risk

Avoid confusing it with CVE-2023-23397

CVE-2023-23397 is a different Outlook vulnerability involving credential-theft behavior. Do not combine its technical details with CVE-2023-36884. Microsoft’s March 2023 article about that issue is here and should not be used as the primary technical description of CVE-2023-36884.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
15.6 Inch Laptop Computer, N4020, 4GB DDR4 RAM, 128GB eMMC,with Windows 11
  • EFFORTLESS EVERYDAY PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 Home system, delivering reliable, low-power efficiency for daily tasks like document editing, email, online classes, and web browsing
  • 15.6-INCH FULL HD DISPLAY: Enjoy immersive visuals on the 15.6" FHD (1920x1080) anti-glare screen with micro-edge bezels. Delivers clear details and comfortable viewing for long study sessions, working on spreadsheets, and video playback
  • RESPONSIVE MULTITASKING & STORAGE: Built with 4GB LPDDR4 RAM and 128GB eMMC storage for smooth daily essential use. Expand your storage by up to 1TB via the integrated TF card slot to easily store movies, photos, and working files
  • ADVANCED CONNECTIVITY: Outfitted with 2x Full-Featured Type-C ports for data transfer, fast charging, and dual-monitor output, alongside 2x USB 3.2 Gen1 ports and a 3.5mm audio jack for complete peripheral compatibility
  • LIGHTWEIGHT & SILENT OPERATION: Slim and portable for effortless travel or commuting. Features a 1MP HD webcam for remote meetings, 38Wh battery with 45W Type-C fast charging, and a fanless silent design for peaceful work environments.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Enterprise tooling

Organizations may use Intune for policy, application deployment, and compliance reporting (official page), Defender for Endpoint for vulnerability visibility and investigation (official page), Defender for Office 365 for malicious-document delivery controls (official page), or Configuration Manager for established hybrid update operations (official page). None is required to remediate the CVE; the essential action is applying and verifying Microsoft’s supported security updates.

Frequently Asked Questions

Is CVE-2023-36884 still dangerous?

Unpatched systems can remain exposed. The 2023 zero-day phase is historical, but missing applicable Windows or Office updates is still a security defect.

Is the registry setting the same as patching?

No. It is a temporary behavior-blocking mitigation and may affect legitimate functionality; it does not replace a Microsoft security update.

Does Microsoft 365 Apps update automatically?

Not necessarily. Update channels, policy restrictions, deferred servicing, disconnected devices, and failed installations can leave a device behind, so verify the installed build and management compliance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Windows 11 Laptop with i3 Processor 15.6" Work Laptop for College Students
  • 【Efficient Performance】 Powered by Intel Core i3 processor (2 cores, 4 threads, up to 3.4GHz) with 12GB RAM and 256GB SSD. Handles multitasking, office software, online classes, and HD video streaming smoothly. Integrated Intel UHD Graphics 620
  • Backlit Keyboard & Complete Package】Comes with a cool backlit keyboard. Comes with awebcam, dual stereo speakers (8Ω/1.0W each), DC charger, and user manual – ready for late-night studying, online classes, video conferencing, and daily productivity
  • 【Vibrant Display】 15.6-inch Full HD (1920x1080) anti-glare screen with 16:9 aspect ratio delivers crisp images and vivid colors – perfect for studying, watching lectures, or entertainment. Thin-bezel design maximizes viewing area
  • 【Fast Connectivity & Expansion】 Equipped with WiFi 6 (802.11ax) and Bluetooth 5.2 for stable, high-speed wireless. Features 3 x USB 3.0, HDMI 2.1, Type-C (supports PD3.0 fast charging), and a TF card slot expandable up to 2TB – easily connect external monitors, mice, drives, or expand storage for all your files
  • 【Long Battery Life & Portable】 Built-in 11.55V 5000mAh/57.75Wh high-capacity battery delivers approximately 7 hours of mixed-use battery life – enough for a full day of classes and assignments. Lightweight at just 1.63kg (3.6 lbs) and 19.5mm thin, plus a compact packing size – easily slips into a backpack for campus, library, or coffee shop

Does this affect Windows Server?

Applicability depends on the server edition, build, installed components, and updates. Check Microsoft’s live CVE guidance rather than assuming servers are exempt.

Can the mitigation be removed after patching?

Remove it only after the applicable updates and compliance are verified, and follow Microsoft’s current guidance and your organization’s change process.

The Bottom Line

Install and verify the applicable Windows and Office security updates first. Keep the 2023 registry policy only as a documented, tested temporary mitigation when Microsoft’s current guidance calls for it; it is not a substitute for patching.

Quick Recap

Bestseller No. 1
SaleBestseller No. 2
Dell Latitude 5420 14' FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
Dell Latitude 5420 14" FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
256 GB SSD of storage.; Multitasking is easy with 16GB of RAM; Equipped with a blazing fast Core i5 2.00 GHz processor.
$260.00
Bestseller No. 3
HP 14' HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Pink (Renewed)
HP 14" HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Pink (Renewed)
14" diagonal, 1366x768 resolution, HD BrightView LED, Glossy NON-TOUCH Display
$249.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.