CVE-2021-34478: Microsoft Office Remote Code Execution Vulnerability
Overview
- Severity
- High (CVSS 7.8)
- CVSS Vector
- CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
- Category
- Remote Code Execution
- Exploit Status
- Not Exploited
- Exploitation Likelihood
- Less Likely
- Patch Tuesday
- 2021-Aug
- Released
- 2021-08-10
- Last Updated
- 2021-08-25
- EPSS Score
- 9.48% (percentile: 92.8%)
FAQ
Is the Preview Pane an attack vector for this vulnerability?
No, the Preview Pane is not an attack vector.
According to the CVSS score, user interaction is required to exploit this vulnerability. What kind of user interaction is required?
A user needs to be tricked into running malicious files.
Affected Products (4)
Other
Acknowledgments
Thomas Bouzerar (@MajorTomSec) from Synacktiv (@Synacktiv) working with Trend Micro Zero Day Initiative
Revision History
- 2021-08-10: Information published.
- 2021-08-19: To comprehensively address CVE-2021-24478, Microsoft has released an updated Build for Microsoft 365 Apps installed on Windows 7 and for the Semi-Annual Enterprise Channel: Version 2002. The new Build number is 12527.22021. See Release notes for Microsoft Office security updates for more information.
- 2021-08-25: Added acknowledgements. This is an informational change only.