Junglewise Threat Intelligence

CVE-2021-27059: Microsoft Office Remote Code Execution Vulnerability

CVE-2021-27059 · Severity: critical · CVSS 7.6 · Exploited in the wild · Published 2021-11-03

Technologies: Microsoft Office, Microsoft Office 2016. Vendors: Microsoft.

Executive brief

Microsoft Office contains an unspecified vulnerability that allows for remote code execution. The flaw requires high privileges and user interaction, but can lead to a full compromise of confidentiality, integrity, and availability.

Affected products

  • Microsoft Office 2010 Service Pack 2
  • Microsoft Office 2013 Service Pack 1
  • Microsoft Office 2016 All versions

Timeline

  • 2021-03-11: disclosed: NVD Published Date
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: exploited: Reported as exploited in the wild per CISA KEV entry date.

Related threats