CVE-2021-36941: Microsoft Word Remote Code Execution Vulnerability
Microsoft Word Remote Code Execution Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.52.21080801
Event History
Frequently Asked Questions
What access does an attacker need to exploit this vulnerability?
The CVSS vector indicates local attack vector, no privileges required, low attack complexity, and user interaction required. An attacker would need to get a user to interact with the malicious content or scenario needed for exploitation.
What is the potential impact if exploitation succeeds?
Successful exploitation can result in remote code execution. The CVSS metrics rate confidentiality, integrity, and availability impact as high.
Which Microsoft products are identified as affected?
The listed products are Microsoft 365 Apps for Enterprise, Microsoft 365 Apps, Microsoft Office for macOS, and Microsoft Office 2019 for Mac.