CVE-2021-28453
published 2021-04-13CVE-2021-28453: Microsoft Word Remote Code Execution Vulnerability
PriorityP343high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
4.07%
89.5th percentile
Microsoft Word Remote Code Execution Vulnerability
Affected
38 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_365_apps_for_enterprise | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_2010_service_pack_2 | >= 13.0.0.0 < publication | publication |
| microsoft | microsoft_office_2019 | >= 19.0.0 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_2019_for_mac | >= 16.0.0 < publication | publication |
| microsoft | microsoft_office_online_server | >= 16.0.1 < publication | publication |
| microsoft | microsoft_office_web_apps_2010_service_pack_2 | >= 13.0.0 < publication | publication |
| microsoft | microsoft_office_web_apps_server_2013_service_pack_1 | >= 15.0.1 < publication | publication |
| microsoft | microsoft_sharepoint_enterprise_server_2013_service_pack_1 | >= 15.0.0 < publication | publication |
| microsoft | microsoft_sharepoint_enterprise_server_2016 | >= 16.0.0 < publication | publication |
| microsoft | microsoft_sharepoint_server_2010_service_pack_2 | >= 13.0.0.0 < publication | publication |
| microsoft | microsoft_sharepoint_server_2019 | >= 16.0.0 < publication | publication |
| microsoft | microsoft_word_2010_service_pack_2 | >= 13.0.0.0 < publication | publication |
| microsoft | microsoft_word_2013_service_pack_1 | >= 15.0.1 < publication | publication |
| microsoft | microsoft_word_2016 | >= 16.0.1 < publication | publication |
| microsoft | office | — | — |
| microsoft | office_web_apps | — | — |
| microsoft | office_web_apps_server | — | — |
| microsoft | sharepoint_server | — | — |
| microsoft | sharepoint_server | — | — |
| microsoft | sharepoint_server | — | — |
| microsoft | sharepoint_server | — | — |
| microsoft | word | — | — |
| microsoft | word | — | — |
| microsoft | word | — | — |
| msrc | microsoft_365_apps | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2qcm-m6xq-w233: Microsoft Word Remote Code Execution Vulnerability
ghsa_unreviewed·2022-05-24
CVE-2021-28453 [HIGH] GHSA-2qcm-m6xq-w233: Microsoft Word Remote Code Execution Vulnerability
Microsoft Word Remote Code Execution Vulnerability
Microsoft
Microsoft Word Remote Code Execution Vulnerability
vendor_msrc·2021-04-13·CVSS 7.8
CVE-2021-28453 [HIGH] Microsoft Word Remote Code Execution Vulnerability
Microsoft Word Remote Code Execution Vulnerability
FAQ: Is the Preview Pane an attack vector for this vulnerability?
No, the Preview Pane is not an attack vector.
Microsoft Office Word: Microsoft Office Word
Microsoft: Microsoft
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://www.microsoft.com/downloads/details.aspx?familyid=dd0af276-336a-4fce-9e7f-19d1f7d04140
Reference: https://www.microsoft.com/downloads/details.aspx?familyid=481cf107-d69d-45b2-ba83-16c03501998c
Reference: https://www.microsoft.com/downloads/details.aspx?familyid=556df453-a607-4250-8eaf-9a8c6c8d71b8
Reference: https://www.microsoft.com/downloads/details.asp
No detection rules found.
No public exploits indexed.
Krebs
Microsoft Patch Tuesday, April 2021 Edition
blogs_krebs·2021-04-13·CVSS 7.8
[HIGH] Microsoft Patch Tuesday, April 2021 Edition
Microsoft today released updates to plug at least 110 security holes in its Windows operating systems and other products. The patches include four security fixes for Microsoft Exchange Server — the same systems that have been besieged by attacks on four separate (and zero-day) bugs in the email software over the past month. Redmond also patched a Windows flaw that is actively being exploited in the wild.
Nineteen of the vulnerabilities fixed this month earned Microsoft’s most-dire “Critical” label, meaning they could be used by malware or malcontents to seize remote control over vulnerable Windows systems without any help from users.
Microsoft released updates to fix four more flaws in Exchange Server versions 2013-2019 ( CVE-2021-28480 , CVE-2021-28481 , CVE-2021-28482 , CVE-2021-28483
Krebs
Microsoft Patch Tuesday, April 2021 Edition
blogs_krebs·2021-04-13·CVSS 7.8
[HIGH] Microsoft Patch Tuesday, April 2021 Edition
Microsoft today released updates to plug at least 110 security holes in its Windows operating systems and other products. The patches include four security fixes for Microsoft Exchange Server — the same systems that have been besieged by attacks on four separate (and zero-day) bugs in the email software over the past month. Redmond also patched a Windows flaw that is actively being exploited in the wild.
Nineteen of the vulnerabilities fixed this month earned Microsoft’s most-dire “Critical” label, meaning they could be used by malware or malcontents to seize remote control over vulnerable Windows systems without any help from users.
Microsoft released updates to fix four more flaws in Exchange Server versions 2013-2019 (CVE-2021-28480, CVE-2021-28481, CVE-2021-28482, CVE-2021-28483). In
2021-04-13
Published