CVE-2021-27059KEV · OVERDUE

Microsoft Office Remote Code Execution Vulnerability

High · published March 11, 2021

Patch now

Confirmed exploited, and the score agrees

CVSS calls it high at 7.6. It is confirmed in active exploitation. It sits in the 92.9th percentile for exploit probability.

1754
days past CISA
deadline
CVSS v3.1
7.6
EPSS
6%
Percentile
92.9
In the wild
Confirmed
What it is

🚨 A simple document could let an attacker execute code on your system! This Microsoft Office vulnerability is like inviting a stranger to your party—and they can take over your speakers! 🔥 Think of this like a sneaky pizza delivery—a seemingly harmless box arrives at your door, but inside is a malware-laden surprise that can infect your entire home network. Just like accepting any delivery without checking could cause chaos, so can opening a malicious Office file. An attacker exploiting this vulnerability could remotely control your system, enabling them to install software, access sensitive data, or even create new accounts with full user rights. The potential for data breaches and system compromises is absolutely devastating! ⚡

Put simply

Think of this like a sneaky pizza delivery—a seemingly harmless box arrives at your door, but inside is a malware-laden surprise that can infect your entire home network. Just like accepting any delivery without checking could cause chaos, so can opening a malicious Office file. This CVE-2021-27059 vulnerability in Microsoft Office allows attackers to execute arbitrary code by tricking users into opening a specially crafted file. Once executed, it bypasses normal protections, leading to a full compromise of the user’s system.

What to do

An attacker exploiting this vulnerability could remotely control your system, enabling them to install software, access sensitive data, or even create new accounts with full user rights. The potential for data breaches and system compromises is absolutely devastating! ⚡ To protect yourself, update Microsoft Office to the latest version immediately. Ensure that your security settings are configured to block potentially harmful files and regularly train staff on recognizing phishing attempts. 🛡️ You've got this! Patch those systems and keep your environment secure! 💪✨

The record
Technical detail
CVSS v3.1
7.6 · HIGH
Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.06076 · 92.9th percentile
Published
2021-03-11T21:15Z
KEV added
2021-11-03 · due 2021-11-17
Affected products (5)
ProductVersionsFixed in
microsoft/officeall versions
microsoft/officeall versions
microsoft/officeall versions
microsoft/office_2016all versions
microsoft/office_2016all versions
References (3)
EPSS history
Timeline
  • 03 NOV 00:00Z
    Added to CISA KEV — remediate by Nov 17
    kev
  • 11 MAR 15:49Z
    Microsoft Office Remote Code Execution Vulnerability
    cvelistv5