cbcvebase.
CVE-2021-27059
published 2021-03-11

CVE-2021-27059: Microsoft Office Remote Code Execution Vulnerability

PriorityP276medium6.5CVSS 3.1
AVLACLPRHUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2021-11-17
Exploited in the wild
EPSS
3.18%
86.6th percentile
Microsoft Office Remote Code Execution Vulnerability

Affected

10 ranges
VendorProductVersion rangeFixed in
microsoftmicrosoft_office_2010_service_pack_2>= 13.0.0.0 < publicationpublication
microsoftmicrosoft_office_2013_service_pack_1>= 15.0.0 < publicationpublication
microsoftmicrosoft_office_2016>= 16.0.0 < publicationpublication
microsoftoffice
microsoftoffice
microsoftoffice
msrcmicrosoft_office_2010_service_pack_2
msrcmicrosoft_office_2013_rt_service_pack_1
msrcmicrosoft_office_2013_service_pack_1
msrcmicrosoft_office_2016

Detection & IOCsextracted from sources · hover to see the quote

  • Preview Pane is NOT an attack vector; exploitation requires user interaction (opening a malicious Office document)
  • Vulnerability has been confirmed exploited in the wild across both latest and older software releases — prioritize detection on Microsoft Office process execution chains
  • ·No technical details, file hashes, network indicators, or exploit specifics are publicly disclosed for this CVE across the provided sources. Detection must rely on patch-state verification and behavioral monitoring of Microsoft Office.

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
nvdv2.08.5HIGHAV:N/AC:M/Au:S/C:C/I:C/A:C
vulncheck7.6HIGH
cisa6.5MEDIUM
vendor_msrc7.6HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.