CVE-2021-31194
published 2021-05-11CVE-2021-31194: OLE Automation Remote Code Execution Vulnerability
PriorityP355high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
2.35%
81.8th percentile
OLE Automation Remote Code Execution Vulnerability
Affected
50 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1507 | >= 10.0.0 < 10.0.10240.18931 | 10.0.10240.18931 |
| microsoft | windows_10_version_1607 | >= 10.0.0 < 10.0.14393.4401 | 10.0.14393.4401 |
| microsoft | windows_10_version_1803 | >= 10.0.0 < 10.0.17134.2207 | 10.0.17134.2207 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.1935 | 10.0.17763.1935 |
| microsoft | windows_10_version_1909 | >= 10.0.0 < 10.0.18363.1556 | 10.0.18363.1556 |
| microsoft | windows_10_version_2004 | >= 10.0.0 < 10.0.19041.982 | 10.0.19041.982 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.982 | 10.0.19042.982 |
| microsoft | windows_7 | >= 6.1.0 < 6.1.7601.24597 | 6.1.7601.24597 |
| microsoft | windows_7 | >= 6.1.0 < 6.1.7601.24598 | 6.1.7601.24598 |
| microsoft | windows_7_service_pack_1 | >= 6.1.0 < 6.1.7601.24597 | 6.1.7601.24597 |
| microsoft | windows_7_service_pack_1 | >= 6.1.0 < 6.1.7601.24598 | 6.1.7601.24598 |
| microsoft | windows_8.1 | >= 6.3.0 < 6.3.9600.20017 | 6.3.9600.20017 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.0.0 < 6.1.7601.24597 | 6.1.7601.24597 |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.0.0 < 6.1.7601.24598 | 6.1.7601.24598 |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.0 < 6.1.7601.24597 | 6.1.7601.24597 |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.0 < 6.1.7601.24598 | 6.1.7601.24598 |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.0 < 6.0.6003.21117 | 6.0.6003.21117 |
| microsoft | windows_server_2012 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
snort↗
57539, 57540, 57542 - 57545 and 57548 - 57550
- →CVE-2021-31194 affects OLE Automation (an inter-process communication mechanism); monitor for anomalous OLE Automation activity that does not require user interaction, as exploitation requires no user interaction. ↗
- ·The Snort rule set (SIDs 57539, 57540, 57542–57545, 57548–57550) covers multiple May 2021 Patch Tuesday CVEs collectively, not exclusively CVE-2021-31194; rule applicability to this specific CVE should be verified against the Snort advisory. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9p8q-xhf5-83rg: OLE Automation Remote Code Execution Vulnerability
ghsa_unreviewed·2022-05-24
CVE-2021-31194 [HIGH] GHSA-9p8q-xhf5-83rg: OLE Automation Remote Code Execution Vulnerability
OLE Automation Remote Code Execution Vulnerability
Microsoft
OLE Automation Remote Code Execution Vulnerability
vendor_msrc·2021-05-11·CVSS 8.8
CVE-2021-31194 [HIGH] OLE Automation Remote Code Execution Vulnerability
OLE Automation Remote Code Execution Vulnerability
Windows OLE: Windows OLE
Microsoft: Microsoft
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5003174
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5003171
Reference: https://support.microsoft.com/help/5003171
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5003169
Reference: https://support.microsoft.com/help/5003169
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5003173
Reference: https://support.microsoft.com/help/5003173
Reference: https://cata
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday for May 2021 — Snort rules and prominent vulnerabilities
blogs_talos·2021-05-11·CVSS 9.8
[CRITICAL] Microsoft Patch Tuesday for May 2021 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for May 2021 — Snort rules and prominent vulnerabilities
By Jon Munshaw, with contributions from Chris Neal.
Microsoft released its monthly security update Tuesday, disclosing 55 vulnerabilities across its suite of products, the fewest in any month since January 2020.
There are only three critical vulnerabilities patched in this month, while two are of “moderate” severity and the rest are “important.” All three critical vulnerabilities, however, are considered "more likely” to be exploited, according to Microsoft.
This month’s security update provides patches for several major pieces of software, including Microsoft Office, SharePoint and Windows’ wireless networking. For a full rundown of these CVEs, head to Microsoft’s security update page .
Talos also rel
Qualys
Microsoft & Adobe Patch Tuesday (May 2021) – Qualys covers 85 Vulnerabilities, 26 Critical
blogs_qualys·2021-05-11·CVSS 9.9
CVE-2021-31181 [CRITICAL] Microsoft & Adobe Patch Tuesday (May 2021) – Qualys covers 85 Vulnerabilities, 26 Critical
## Microsoft Patch Tuesday – May 2021
Microsoft patched 55 CVEs in their May 2021 Patch Tuesday release, of which 4 are rated as critical severity. Three 0-day vulnerability patches were included in the release. As of this publication date, none have been exploited.
Qualys released 12 QIDs on the same day, providing vulnerability detection and patch management coverage (where applicable) for all 55 CVEs and the related KBs.
## Critical Microsoft vulnerabilities patched:
CVE-2021-31181 – SharePoint Remote Code Execution Vulnerability
Microsoft released patches addressing a critical RCE vulnerability in SharePoint (CVE-2021-31181). This CVE has a high likelihood of exploitability and is assigned a CVSSv3 base score of 8.8 by the vendor.
CVE-2021-31166 – HTTP Protocol Stack Remote Code
Talos
Microsoft Patch Tuesday for May 2021 — Snort rules and prominent vulnerabilities
blogs_talos·2021-05-11·CVSS 7.5
[HIGH] Microsoft Patch Tuesday for May 2021 — Snort rules and prominent vulnerabilities
By Jon Munshaw, with contributions from Chris Neal.
Microsoft released its monthly security update Tuesday, disclosing 55 vulnerabilities across its suite of products, the fewest in any month since January 2020.
There are only three critical vulnerabilities patched in this month, while two are of “moderate” severity and the rest are “important.” All three critical vulnerabilities, however, are considered "more likely” to be exploited, according to Microsoft.
This month’s security update provides patches for several major pieces of software, including Microsoft Office, SharePoint and Windows’ wireless networking. For a full rundown of these CVEs, head to Microsoft’s security update page.
Talos also released a new set of SNORTⓇ rules that provide coverage for some of these vulnerabilitie
Crowdstrike
May 2021 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] May 2021 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Crowdstrike
May 2021 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] May 2021 Patch Tuesday: Updates and Analysis
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
2021-05-11
Published