CVE-2021-27057: Microsoft Office Graph Uninitialized Variable Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
Other sources
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Office. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the Graph COM object. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of the current process.
— ZDI
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.5327.1000Patch KB4493203 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.5327.1000Patch KB4493234 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.7266.5000Patch KB4493214 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.5327.1000Patch KB4493239 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.7266.5000Patch KB4504707 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4493203 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4493239 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5134.1000Patch KB4493200 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5134.1000Patch KB4493233 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10372.20000Patch KB4493229
Event History
Frequently Asked Questions
What is CVE-2021-27057?
CVE-2021-27057 is a vulnerability that allows remote attackers to execute arbitrary code on affected installations of Microsoft Office.
How can remote attackers exploit CVE-2021-27057?
Remote attackers can exploit CVE-2021-27057 by having the target visit a malicious page or open a malicious file.
What is the severity of CVE-2021-27057?
CVE-2021-27057 has a severity score of 7.8 out of 10, indicating a high severity.
Which versions of Microsoft Office are affected by CVE-2021-27057?
CVE-2021-27057 affects various versions of Microsoft Office, including Office Online Server, Office 2019, Office 2016, Office 2013, Excel 2013, and Excel 2010.
How can I fix CVE-2021-27057?
To fix CVE-2021-27057, update your affected installations of Microsoft Office by applying the patches provided by Microsoft.