CVE-2021-24108: Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5134.1000Patch KB4493225 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.5327.1000Patch KB4493228 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4493228 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.7266.5000Patch KB4504703
Event History
Frequently Asked Questions
What is the severity of CVE-2021-24108?
CVE-2021-24108 has a critical severity rating due to its potential for remote code execution.
How do I fix CVE-2021-24108?
To fix CVE-2021-24108, you should apply the latest security updates provided by Microsoft for the affected Office applications.
Which Microsoft Office versions are affected by CVE-2021-24108?
CVE-2021-24108 affects multiple versions including Microsoft Office 2010 SP2, 2013 SP1, 2016, 2019, and Microsoft 365 Apps.
What type of vulnerability is CVE-2021-24108?
CVE-2021-24108 is classified as a remote code execution vulnerability.
What might happen if CVE-2021-24108 is exploited?
Exploiting CVE-2021-24108 could allow an attacker to execute arbitrary code on the vulnerable system.