CVE-2021-38659: Microsoft Office Graphics Remote Code Execution Vulnerability
Microsoft Office Graphics Remote Code Execution Vulnerability
Other sources
Microsoft Office Remote Code Execution Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases
Event History
Frequently Asked Questions
What is CVE-2021-38659?
CVE-2021-38659 is a vulnerability that allows remote attackers to execute arbitrary code on affected installations of Microsoft PowerPoint.
How can CVE-2021-38659 be exploited?
CVE-2021-38659 can be exploited when a user visits a malicious page or opens a malicious file.
What is the severity of CVE-2021-38659?
The severity of CVE-2021-38659 is high, with a CVSS score of 7.8.
Which software products are affected by CVE-2021-38659?
Microsoft PowerPoint and Microsoft 365 Apps for Enterprise are affected by CVE-2021-38659.
How can I fix CVE-2021-38659?
To fix CVE-2021-38659, apply the security updates provided by Microsoft for the affected software products.