CVE-2021-42275: Microsoft COM for Windows Remote Code Execution Vulnerability
Microsoft COM for Windows Remote Code Execution Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20174Patch KB5007247 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20174Patch KB5007255 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.25769Patch KB5007233 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.21282Patch KB5007246 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.23517Patch KB5007245 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.4770Patch KB5007192 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19041.1348Patch KB5007186 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19042.1348Patch KB5007186 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.19119Patch KB5007207 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19043.1348Patch KB5007186 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.18363.1916Patch KB5007189 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.350Patch KB5007205 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.2300Patch KB5007206
Event History
Frequently Asked Questions
What is CVE-2021-42275?
CVE-2021-42275 is a vulnerability in Microsoft COM for Windows that allows remote code execution.
Which software versions are affected by CVE-2021-42275?
Microsoft Windows 10, Windows 11, Windows 7, Windows 8.1, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows Server 2016, Windows Server 2019, and Windows Server 2022 are affected by CVE-2021-42275.
What is the severity of CVE-2021-42275?
CVE-2021-42275 has a severity score of 8.8 out of 10 (high severity).
How can I fix CVE-2021-42275?
Apply the security patch provided by Microsoft to address the vulnerability.
Where can I find more information about CVE-2021-42275?
You can find more information about CVE-2021-42275 on the Microsoft Security Guidance Advisory at [https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-42275](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-42275).