CVE-2021-38657HighCVSS 6.1

Microsoft Office Graphics Component Information Disclosure Vulnerability

Published
September 14, 2021
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

What type of information could be disclosed by this vulnerability? The type of information that could be disclosed if an attacker successfully exploited this vulnerability is uninitialized memory.

Is the Preview Pane an attack vector for this vulnerability? No, the Preview Pane is not an attack vector.

🎯 Affected products2

  • Microsoft 365 Apps for Enterprise for 32-bit Systems
  • Microsoft 365 Apps for Enterprise for 64-bit Systems

✅ Remediation

KBClick to Run (Security Update) — fixed build https://aka.ms/OfficeSecurityReleases

🔗 References (2)