Junglewise Threat Intelligence

CVE-2021-38646: Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability

CVE-2021-38646 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-03-28

Technologies: Microsoft Office, Microsoft Office 2016, Microsoft 365 Apps for Enterprise, Microsoft Office 2019. Vendors: Microsoft.

Executive brief

The Microsoft Office Access Connectivity Engine contains a vulnerability that allows for remote code execution when a user opens a specially crafted file. The flaw stems from an unspecified memory corruption issue within the engine used by various Microsoft Office products.

Affected products

  • Microsoft Office 2013 Service Pack 1
  • Microsoft Office 2016
  • Microsoft Office 2019
  • Microsoft Microsoft 365 Apps for Enterprise
  • Microsoft Office Access Connectivity Engine

Timeline

  • 2021-09-15: disclosed: NVD Published Date
  • 2022-03-28: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats