CVE-2021-34478HighCVSS 7.8

Microsoft Office Remote Code Execution Vulnerability

Published
August 10, 2021
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? A user needs to be tricked into running malicious files.

Is the Preview Pane an attack vector for this vulnerability? No, the Preview Pane is not an attack vector.

🎯 Affected products4

  • Microsoft 365 Apps for Enterprise for 32-bit Systems
  • Microsoft 365 Apps for Enterprise for 64-bit Systems
  • Microsoft Office 2019 for 32-bit editions
  • Microsoft Office 2019 for 64-bit editions

✅ Remediation

KBClick to Run (Security Update) — fixed build https://aka.ms/OfficeSecurityReleases

🔗 References (2)