CVE-2021-38658: Microsoft Office Graphics Remote Code Execution Vulnerability
Microsoft Office Graphics Remote Code Execution Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5215.1000Patch KB5002005 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5381.1000Patch KB5002007
Event History
Frequently Asked Questions
What is CVE-2021-38658?
CVE-2021-38658 is a vulnerability that allows remote attackers to execute arbitrary code on affected installations of Microsoft Office.
How severe is CVE-2021-38658?
CVE-2021-38658 has a severity rating of 7.8, which is considered high.
Which versions of Microsoft Office are affected by CVE-2021-38658?
Microsoft Office 2013, 2016, and 2019 (32-bit and 64-bit editions) are affected by CVE-2021-38658.
How can I fix CVE-2021-38658?
To fix CVE-2021-38658, you should apply the relevant patches provided by Microsoft for your specific version of Microsoft Office.
Where can I find more information about CVE-2021-38658?
You can find more information about CVE-2021-38658 on the Microsoft Security Response Center website, the Zero Day Initiative's advisory, and the Microsoft Update Guide.