CVE-2021-27055: Microsoft Visio Security Feature Bypass Vulnerability
Microsoft Visio Security Feature Bypass Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.7266.5000Patch KB4484376 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.5327.1000Patch KB4486673 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5134.1000Patch KB4493151
Event History
Frequently Asked Questions
What is CVE-2021-27055?
CVE-2021-27055 is a security feature bypass vulnerability in Microsoft Visio.
How severe is CVE-2021-27055?
CVE-2021-27055 has a severity value of 7, which is considered high.
Which software is affected by CVE-2021-27055?
The following software versions are affected: Microsoft 365 Apps, Microsoft Office 2019, Microsoft Visio 2010 SP2, Microsoft Visio 2013 SP1, and Microsoft Visio 2016.
How can I fix CVE-2021-27055?
To fix CVE-2021-27055, it is recommended to install the latest security updates provided by Microsoft.
Where can I find more information about CVE-2021-27055?
You can find more information about CVE-2021-27055 on the Microsoft Security Guidance Advisory page: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-27055