CVE-2021-28455
published 2021-05-11CVE-2021-28455: Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability
PriorityP356high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
2.12%
79.9th percentile
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability
Affected
58 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_365_apps_for_enterprise | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_access_2013_service_pack_1 | >= 15.0.0 < 15.0.5353.1000 | 15.0.5353.1000 |
| microsoft | microsoft_access_2016 | >= 16.0.0 < publication | publication |
| microsoft | microsoft_office_2013_service_pack_1 | >= 15.0.0 < 15.0.5345.1001 | 15.0.5345.1001 |
| microsoft | microsoft_office_2016 | >= 16.0.0 < 16.0.5161.1001 | 16.0.5161.1001 |
| microsoft | microsoft_office_2019 | >= 19.0.0 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1507 | >= 10.0.0 < 10.0.10240.18931 | 10.0.10240.18931 |
| microsoft | windows_10_version_1607 | >= 10.0.0 < 10.0.14393.4401 | 10.0.14393.4401 |
| microsoft | windows_10_version_1803 | >= 10.0.0 < 10.0.17134.2207 | 10.0.17134.2207 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.1935 | 10.0.17763.1935 |
| microsoft | windows_10_version_1909 | >= 10.0.0 < 10.0.18363.1556 | 10.0.18363.1556 |
| microsoft | windows_10_version_2004 | >= 10.0.0 < 10.0.19041.982 | 10.0.19041.982 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.982 | 10.0.19042.982 |
| microsoft | windows_7 | >= 6.1.0 < 6.1.7601.24597 | 6.1.7601.24597 |
| microsoft | windows_7 | >= 6.1.0 < 6.1.7601.24598 | 6.1.7601.24598 |
| microsoft | windows_7_service_pack_1 | >= 6.1.0 < 6.1.7601.24597 | 6.1.7601.24597 |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect outbound SMB or WebDAV (UNC path) connections originating from IIS worker processes (w3wp.exe) or SQL Server (sqlservr.exe) — these indicate Jet/ACE remote database access being triggered, which is the core attack primitive for CVE-2021-28455. ↗
- →Monitor for SQL queries containing remote database path prefixes (UNC paths) in MS Jet queries, or use of OPENDATASOURCE, OPENROWSET, or addlinkedserver in SQL Server — these are the SQL-level indicators of exploitation attempts. ↗
- →Block WebDAV traffic traversing from trusted to untrusted network zones as a network-level detection/prevention control for CVE-2021-28455 exploitation. ↗
- →Alert on CreateFile calls to UNC paths issued by msjet40.dll or acecore.dll loaded within IIS (w3wp.exe) or SQL Server (sqlservr.exe) processes — this is the low-level OS call triggered during remote Jet database access. ↗
- ·The mitigation for ACE (Access Connectivity Engine) remains incomplete even after the May 2021 patch — environments using ACE remain at elevated risk. ↗
- ·The vulnerability is exploitable under SQL injection or ad hoc query scenarios — any component on Windows that allows user-controlled SQL queries via MS Jet or ACE is in scope, not just IIS and SQL Server. ↗
- ·Re-enabling AllowQueryRemoteTables after disabling it reintroduces the vulnerability; Microsoft explicitly warns against this. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability
vendor_msrc·2021-05-11·CVSS 8.8
CVE-2021-28455 [HIGH] Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability
FAQ: Is the Preview Pane an attack vector for this vulnerability?
No, the Preview Pane is not an attack vector.
FAQ: How do the security updates address this vulnerability?
The security updates address the vulnerability by providing the ability to configure the Jet Red Database Engine or Access Connectivity Engine to block access to remote databases. You might need to do this when you allow unprivileged users to run custom SQL queries in JET or ACE. See KB5002984: Configuring Jet Red Database Engine and Access Connectivity Engine to block access to remote databases for more information.
If I do not disable these SQL queries, is there any other way I can be protected from this vulnerabilit
GHSA
GHSA-2m6v-mggf-5f9g: Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability
ghsa_unreviewed·2022-05-24
CVE-2021-28455 [HIGH] CWE-77 GHSA-2m6v-mggf-5f9g: Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability
No detection rules found.
No public exploits indexed.
Unit42
Palo Alto Networks Discloses New Attack Surface Targeting Microsoft IIS and SQL Server at Black Hat Asia 2021
blogs_unit42·2021-07-30
Palo Alto Networks Discloses New Attack Surface Targeting Microsoft IIS and SQL Server at Black Hat Asia 2021
Threat Research Center
Threat Research
Vulnerabilities
## Palo Alto Networks Discloses New Attack Surface Targeting Microsoft IIS and SQL Server at Black Hat Asia 2021
Tao Yan
Qi Deng
Bo Qu
Zhibin Zhang
Published: July 30, 2021
Threat Research
Vulnerabilities
Attack surface
Black Hat
Exploit
IIS
JET
SQL
## Executive Summary
Unit 42 recently shared information about a new attack surface targeting Microsoft Internet Information Services (IIS) and SQL Server at Black Hat Asia 2021. In our presentation , we introduced a previously undisclosed technique to execute SQL queries on the remote database in IIS and SQL Server under SQL injection or ad hoc scenarios. We also discussed three typical cases picked from around 100 Jet vulnerabilities that we discovered in a three-mon
Unit42
Palo Alto Networks Discloses New Attack Surface Targeting Microsoft IIS and SQL Server at Black Hat Asia 2021
blogs_unit42·2021-07-30
Palo Alto Networks Discloses New Attack Surface Targeting Microsoft IIS and SQL Server at Black Hat Asia 2021
## Executive Summary
Unit 42 recently shared information about a new attack surface targeting Microsoft Internet Information Services (IIS) and SQL Server at Black Hat Asia 2021. In our presentation, we introduced a previously undisclosed technique to execute SQL queries on the remote database in IIS and SQL Server under SQL injection or ad hoc scenarios. We also discussed three typical cases picked from around 100 Jet vulnerabilities that we discovered in a three-month period. Here, we cover the details of the technique, which allows threat actors to remotely attack IIS and SQL Server to gain SYSTEM privilege by using Microsoft Jet Database Engine vulnerabilities.
In response to this research, Microsoft released a complex patch to mitigate this attack surface. However, the patch is turn
Qualys
Microsoft & Adobe Patch Tuesday (May 2021) – Qualys covers 85 Vulnerabilities, 26 Critical
blogs_qualys·2021-05-11·CVSS 9.9
CVE-2021-31181 [CRITICAL] Microsoft & Adobe Patch Tuesday (May 2021) – Qualys covers 85 Vulnerabilities, 26 Critical
## Microsoft Patch Tuesday – May 2021
Microsoft patched 55 CVEs in their May 2021 Patch Tuesday release, of which 4 are rated as critical severity. Three 0-day vulnerability patches were included in the release. As of this publication date, none have been exploited.
Qualys released 12 QIDs on the same day, providing vulnerability detection and patch management coverage (where applicable) for all 55 CVEs and the related KBs.
## Critical Microsoft vulnerabilities patched:
CVE-2021-31181 – SharePoint Remote Code Execution Vulnerability
Microsoft released patches addressing a critical RCE vulnerability in SharePoint (CVE-2021-31181). This CVE has a high likelihood of exploitability and is assigned a CVSSv3 base score of 8.8 by the vendor.
CVE-2021-31166 – HTTP Protocol Stack Remote Code
Crowdstrike
May 2021 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] May 2021 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Crowdstrike
May 2021 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] May 2021 Patch Tuesday: Updates and Analysis
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
2021-05-11
Published