First published: Tue Sep 14 2021(Updated: )
Microsoft Office Visio Remote Code Execution Vulnerability
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office Visio | ||
Microsoft Office 2019 for 32-bit editions | ||
Microsoft 365 Apps for Enterprise | ||
Microsoft 365 Apps for Enterprise | ||
Microsoft Office 2019 for 64-bit editions | ||
Microsoft 365 Apps | ||
Microsoft Office | =2019 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-38654 is high (7.8).
CVE-2021-38654 allows remote code execution through the parsing of malicious EMF files in Microsoft Office Visio.
CVE-2021-38654 affects Microsoft Office Visio, Microsoft Office 2019, and Microsoft 365 Apps for Enterprise.
Yes, user interaction is required to exploit CVE-2021-38654. The target must visit a malicious page or open a malicious file.
You can find more information about CVE-2021-38654 on the Microsoft Security Response Center (MSRC) website and the Zero Day Initiative (ZDI) advisory.