CVE-2021-36941HighCVSS 7.8
Microsoft Word Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? A user needs to be tricked into running malicious files.
Is the Preview Pane an attack vector for this vulnerability? No, the Preview Pane is not an attack vector.
🎯 Affected products3
- Microsoft 365 Apps for Enterprise for 32-bit Systems
- Microsoft 365 Apps for Enterprise for 64-bit Systems
- Microsoft Office 2019 for Mac
✅ Remediation
KBRelease Notes (Security Update) — fixed build 16.52.21080801 KBClick to Run (Security Update) — fixed build https://aka.ms/OfficeSecurityReleases