CVE-2021-27055
published 2021-03-11CVE-2021-27055: Microsoft Visio Security Feature Bypass Vulnerability
PriorityP432high7CVSS 3.1
AVLACHPRNUIRSUCHIHAH
EPSS
2.45%
83.1th percentile
Microsoft Visio Security Feature Bypass Vulnerability
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_365_apps_for_enterprise | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_2019 | >= 19.0.0 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_visio_2010_service_pack_2 | >= 13.0.0.0 < 14.0.7266.5000 | 14.0.7266.5000 |
| microsoft | microsoft_visio_2013_service_pack_1 | >= 15.0.1 < 15.0.5327.1000 | 15.0.5327.1000 |
| microsoft | microsoft_visio_2016 | >= 16.0.1 < 16.0.5134.1000 | 16.0.5134.1000 |
| microsoft | office | — | — |
| microsoft | visio | — | — |
| microsoft | visio | — | — |
| microsoft | visio | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_32-bit_systems | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_64-bit_systems | — | — |
| msrc | microsoft_office_2019_for_32-bit_editions | — | — |
| msrc | microsoft_office_2019_for_64-bit_editions | — | — |
| msrc | microsoft_visio_2010_service_pack_2 | — | — |
| msrc | microsoft_visio_2013_service_pack_1 | — | — |
| msrc | microsoft_visio_2016 | — | — |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_msrc7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Microsoft Office/Visio/365 Apps for Enterprise Local Privilege Escalation
vuldb·2026-08-21·CVSS 7.0
CVE-2021-27055 [HIGH] Microsoft Office/Visio/365 Apps for Enterprise Local Privilege Escalation
A vulnerability was found in Microsoft Office, Visio and 365 Apps for Enterprise. It has been rated as problematic. This affects an unknown part. The manipulation leads to Local Privilege Escalation.
This vulnerability is referenced as CVE-2021-27055. The attack can only be performed from a local environment. No exploit is available.
It is recommended to apply a patch to fix this issue.
GHSA
GHSA-4pfg-92mj-fx5w: Microsoft Visio Security Feature Bypass Vulnerability
ghsa_unreviewed·2022-05-24
CVE-2021-27055 [HIGH] GHSA-4pfg-92mj-fx5w: Microsoft Visio Security Feature Bypass Vulnerability
Microsoft Visio Security Feature Bypass Vulnerability
Microsoft
Microsoft Visio Security Feature Bypass Vulnerability
vendor_msrc·2021-03-09·CVSS 7.0
CVE-2021-27055 [HIGH] Microsoft Visio Security Feature Bypass Vulnerability
Microsoft Visio Security Feature Bypass Vulnerability
FAQ: Is the Preview Pane an attack vector for this vulnerability?
No, the Preview Pane is not an attack vector.
FAQ: What is the attack vector for this vulnerability?
Initially an Administrator would need to set a Group Policy in a specific way. Then, an attacker would then need to modify a macro-enabled template that ships with Excel. Then the attacker needs to convince a target to run that malicious file on a system affected by that Policy.
Microsoft Office Visio: Microsoft Office Visio
Microsoft: Microsoft
Impact: Security Feature Bypass
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://www.microsoft.com
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-03-11
Published