CVE-2021-31941: Microsoft Excel XLS File Parsing Use-After-Free Remote Code Execution Vulnerability
Microsoft Office Graphics Remote Code Execution Vulnerability
Other sources
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Excel. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of XLS files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-31941?
CVE-2021-31941 is a vulnerability that allows remote attackers to execute arbitrary code on affected installations of Microsoft Excel.
How can this vulnerability be exploited?
To exploit this vulnerability, the target must visit a malicious page or open a malicious file.
What is the severity level of CVE-2021-31941?
CVE-2021-31941 has a severity level of high.
Which versions of Microsoft Excel are affected by CVE-2021-31941?
Microsoft Office 2013, 2016, 2019, and Microsoft 365 Apps for Enterprise are affected by CVE-2021-31941.
How can I fix CVE-2021-31941?
You can fix CVE-2021-31941 by applying the security updates provided by Microsoft.