CVE-2021-38650: Microsoft Office Spoofing Vulnerability
Microsoft Office Spoofing Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5381.1000Patch KB4484108 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5215.1000Patch KB4484103 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.53.21091200
Event History
Frequently Asked Questions
What is the severity of CVE-2021-38650?
CVE-2021-38650 is classified as a medium-severity spoofing vulnerability in Microsoft Office.
How do I fix CVE-2021-38650?
To resolve CVE-2021-38650, users should apply the latest security updates provided by Microsoft for affected Office versions.
Which Microsoft products are affected by CVE-2021-38650?
CVE-2021-38650 impacts multiple versions of Microsoft Office including 2013, 2016, 2019, and Microsoft 365 Apps.
What type of attacks can exploit CVE-2021-38650?
CVE-2021-38650 can be exploited by attackers to spoof content within Microsoft Office applications, potentially misleading users.
Are there any workarounds for CVE-2021-38650?
While the best solution for CVE-2021-38650 is to apply updates, users may also consider restricting the use of potentially risky components in Office files.