CVE-2021-43256HighCVSS 7.8
Microsoft Excel Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
Is the Preview Pane an attack vector for this vulnerability? No, the Preview Pane is not an attack vector.
🎯 Affected products13
- Microsoft 365 Apps for Enterprise for 32-bit Systems
- Microsoft 365 Apps for Enterprise for 64-bit Systems
- Microsoft Excel 2013 RT Service Pack 1
- Microsoft Excel 2013 Service Pack 1 (32-bit editions)
- Microsoft Excel 2013 Service Pack 1 (64-bit editions)
- Microsoft Excel 2016 (32-bit edition)
- Microsoft Excel 2016 (64-bit edition)
- Microsoft Office 2019 for 32-bit editions
- Microsoft Office 2019 for 64-bit editions
- Microsoft Office LTSC 2021 for 32-bit editions
- Microsoft Office LTSC 2021 for 64-bit editions
- Microsoft Office Web Apps Server 2013 Service Pack 1
- Office Online Server
✅ Remediation
KB5002097 (Security Update) — fixed build 16.0.10381.20001 KBClick to Run (Security Update) — fixed build https://aka.ms/OfficeSecurityReleases KB5002098 (Security Update) — fixed build 16.0.5254.1000 KB5002105 (Security Update) — fixed build 15.0.5407.1000 KB5002103 (Security Update) — fixed build 15.0.5407.1000
🔗 References (7)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-43256
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=8930dfc7-7951-4390-99ee-ae9131412464
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=1d8261fc-456c-44dc-a6b1-491ff7ebd308
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=8c45fd44-46b7-4989-b060-5c2e9a3eaf5b
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=1ad73c44-e765-475f-9270-6ab7a4e6465e
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=65ac9846-c726-4fa8-98c7-50fbc84ad04a
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=d8924e73-ec3f-44a1-8453-4e7c6738a236