CVE-2021-36941: Microsoft Word Remote Code Execution Vulnerability

Overview

Severity
High (CVSS 7.8)
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Category
Remote Code Execution
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2021-Aug
Released
2021-08-10
EPSS Score
5.01% (percentile: 89.7%)

FAQ

Is the Preview Pane an attack vector for this vulnerability? No, the Preview Pane is not an attack vector. According to the CVSS score, user interaction is required to exploit this vulnerability. What kind of user interaction is required? A user needs to be tricked into running malicious files.

Affected Products (3)

Other

  • 11575
  • 11762
  • 11763

Security Updates (1)

Acknowledgments

Lev Aronsky with <a href="https://alephsecurity.com">Aleph Research by HCL AppScan</a>, Vera Mens with <a href="https://alephsecurity.com">Aleph Security by HCL AppScan</a>

Revision History

  • 2021-08-10: Information published.