CVE-2021-27058
published 2021-03-11CVE-2021-27058: Microsoft Office ClickToRun Remote Code Execution Vulnerability
PriorityP342high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
3.54%
88.5th percentile
Microsoft Office ClickToRun Remote Code Execution Vulnerability
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_365_apps_for_enterprise | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| msrc | microsoft_365_apps_for_enterprise_for_32-bit_systems | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_64-bit_systems | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Office ClickToRun Remote Code Execution Vulnerability
vendor_msrc·2021-03-09·CVSS 7.8
CVE-2021-27058 [HIGH] Microsoft Office ClickToRun Remote Code Execution Vulnerability
Microsoft Office ClickToRun Remote Code Execution Vulnerability
FAQ: Is the Preview Pane an attack vector for this vulnerability?
No, the Preview Pane is not an attack vector.
Microsoft Office: Microsoft Office
Microsoft: Microsoft
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Remediation: Click to Run
VulDB
Microsoft 365 Apps for Enterprise ClickToRun Remote Code Execution
vuldb·2026-08-21·CVSS 7.8
CVE-2021-27058 [HIGH] Microsoft 365 Apps for Enterprise ClickToRun Remote Code Execution
A vulnerability described as critical has been identified in Microsoft 365 Apps for Enterprise. This issue affects some unknown processing of the component ClickToRun. Such manipulation leads to Remote Code Execution.
This vulnerability is documented as CVE-2021-27058. The attack can be executed remotely. There is not any exploit available.
It is best practice to apply a patch to resolve this issue.
GHSA
GHSA-whx5-mmrp-j392: Microsoft Office ClickToRun Remote Code Execution Vulnerability
ghsa_unreviewed·2022-05-24
CVE-2021-27058 [HIGH] GHSA-whx5-mmrp-j392: Microsoft Office ClickToRun Remote Code Execution Vulnerability
Microsoft Office ClickToRun Remote Code Execution Vulnerability
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-03-11
Published