CVE-2021-31984: Power BI Remote Code Execution Vulnerability
Published Jul 13, 2021
·Updated
Power BI Remote Code Execution Vulnerability
Affected Software
2 affected componentsFixes available
Microsoft Power BI Report Server
Microsoft Power BI Desktop<> 2.94.781.0
> 2.94.781.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in > 2.94.781.0
Event History
Jul 13, 2021
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
Jul 14, 2021
CVE Published
via MITRE·05:53 PM
Data Sourced
via MITRE·05:53 PM
DescriptionSeverity
Data Sourced
via NVD·06:15 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2021-31984?
CVE-2021-31984 is a vulnerability that allows remote code execution in Power BI Report Server.
2
How does CVE-2021-31984 impact Power BI Report Server?
CVE-2021-31984 allows an attacker to execute arbitrary code remotely on a vulnerable Power BI Report Server.
3
What is the severity of CVE-2021-31984?
CVE-2021-31984 has a severity rating of 8.8 (high).
4
How can I fix CVE-2021-31984?
To fix CVE-2021-31984, it is recommended to apply the security updates provided by Microsoft.
5
Where can I find more information about CVE-2021-31984?
You can find more information about CVE-2021-31984 on the Microsoft Security Guidance Advisory page: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-31984