CVE-2021-27056
published 2021-03-11CVE-2021-27056: Microsoft PowerPoint Remote Code Execution Vulnerability
PriorityP344high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
4.03%
89.9th percentile
Microsoft PowerPoint Remote Code Execution Vulnerability
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_365_apps_for_enterprise | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_2019 | >= 19.0.0 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_powerpoint_2010_service_pack_2 | >= 13.0.0.0 < 14.0.7266.5000 | 14.0.7266.5000 |
| microsoft | microsoft_powerpoint_2013_service_pack_1 | >= 14.0.0 < 15.0.5327.1000 | 15.0.5327.1000 |
| microsoft | microsoft_powerpoint_2016 | >= 16.0.0 < 16.0.5134.1000 | 16.0.5134.1000 |
| microsoft | office | — | — |
| microsoft | powerpoint | — | — |
| microsoft | powerpoint | — | — |
| microsoft | powerpoint | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_32-bit_systems | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_64-bit_systems | — | — |
| msrc | microsoft_office_2019_for_32-bit_editions | — | — |
| msrc | microsoft_office_2019_for_64-bit_editions | — | — |
| msrc | microsoft_powerpoint_2010_service_pack_2 | — | — |
| msrc | microsoft_powerpoint_2013_rt_service_pack_1 | — | — |
| msrc | microsoft_powerpoint_2013_service_pack_1 | — | — |
| msrc | microsoft_powerpoint_2016 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft PowerPoint Remote Code Execution Vulnerability
vendor_msrc·2021-03-09·CVSS 7.8
CVE-2021-27056 [HIGH] Microsoft PowerPoint Remote Code Execution Vulnerability
Microsoft PowerPoint Remote Code Execution Vulnerability
FAQ: Is the Preview Pane an attack vector for this vulnerability?
No, the Preview Pane is not an attack vector.
Microsoft Office PowerPoint: Microsoft Office PowerPoint
Microsoft: Microsoft
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Remediation: Click to Run
Reference: https://www.microsoft.com/downloads/details.aspx?familyid=7e104089-5221-4a5c-8690-676913f41bbc
Reference: https://www.microsoft.com/downloads/details.aspx?familyid=49292ebf-ee21-4f19-a0bf-7a8c45b5066d
Reference: https://www.microsoft.com/downloads/details.aspx?familyid=7f60e48e-c364-4781-87ea-36add17442be
Reference: ht
VulDB
Microsoft Office up to 2019 PowerPoint Remote Code Execution
vuldb·2026-08-21·CVSS 7.8
CVE-2021-27056 [HIGH] Microsoft Office up to 2019 PowerPoint Remote Code Execution
A vulnerability has been found in Microsoft Office up to 2019 and classified as critical. This impacts an unknown function of the component PowerPoint. This manipulation causes Remote Code Execution.
This vulnerability is handled as CVE-2021-27056. The attack can be initiated remotely. There is not any exploit available.
To fix this issue, it is recommended to deploy a patch.
GHSA
GHSA-4w52-x9c4-c723: Microsoft PowerPoint Remote Code Execution Vulnerability
ghsa_unreviewed·2022-05-24
CVE-2021-27056 [HIGH] GHSA-4w52-x9c4-c723: Microsoft PowerPoint Remote Code Execution Vulnerability
Microsoft PowerPoint Remote Code Execution Vulnerability
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-03-11
Published