CVE-2021-34478: Microsoft Office Remote Code Execution Vulnerability

Overview

Severity
High (CVSS 7.8)
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Category
Remote Code Execution
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2021-Aug
Released
2021-08-10
Last Updated
2021-08-25
EPSS Score
9.48% (percentile: 92.8%)

FAQ

Is the Preview Pane an attack vector for this vulnerability? No, the Preview Pane is not an attack vector. According to the CVSS score, user interaction is required to exploit this vulnerability. What kind of user interaction is required? A user needs to be tricked into running malicious files.

Affected Products (4)

Other

  • 11573
  • 11574
  • 11762
  • 11763

Acknowledgments

Thomas Bouzerar (@MajorTomSec) from Synacktiv (@Synacktiv) working with Trend Micro Zero Day Initiative

Revision History

  • 2021-08-10: Information published.
  • 2021-08-19: To comprehensively address CVE-2021-24478, Microsoft has released an updated Build for Microsoft 365 Apps installed on Windows 7 and for the Semi-Annual Enterprise Channel: Version 2002. The new Build number is 12527.22021. See Release notes for Microsoft Office security updates for more information.
  • 2021-08-25: Added acknowledgements. This is an informational change only.