cbcvebase.
CVE-2021-34501
published 2021-07-14

CVE-2021-34501: Microsoft Excel Remote Code Execution Vulnerability

PriorityP267high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
53.18%
98.9th percentile
Microsoft Excel Remote Code Execution Vulnerability

Affected

19 ranges
VendorProductVersion rangeFixed in
microsoftexcel
microsoftexcel
microsoftmicrosoft_365_apps_for_enterprise>= 16.0.1 < https://aka.ms/OfficeSecurityReleaseshttps://aka.ms/OfficeSecurityReleases
microsoftmicrosoft_excel_2013_service_pack_1>= 15.0.0.0 < 15.0.5363.100015.0.5363.1000
microsoftmicrosoft_excel_2016>= 16.0.0.0 < 16.0.5188.10016.0.5188.100
microsoftmicrosoft_excel_2016>= 16.0.0.0 < 16.0.5188.100016.0.5188.1000
microsoftmicrosoft_office_2019>= 19.0.0 < https://aka.ms/OfficeSecurityReleaseshttps://aka.ms/OfficeSecurityReleases
microsoftmicrosoft_office_2019_for_mac>= 16.0.0 < 16.51.210711.0116.51.210711.01
microsoftmicrosoft_office_online_server>= 16.0.1 < 16.0.10376.2000116.0.10376.20001
microsoftoffice
msrcmicrosoft_365_apps_for_enterprise_for_32-bit_systems
msrcmicrosoft_365_apps_for_enterprise_for_64-bit_systems
msrcmicrosoft_excel_2013_rt_service_pack_1
msrcmicrosoft_excel_2013_service_pack_1
msrcmicrosoft_excel_2016
msrcmicrosoft_office_2019_for_32-bit_editions
msrcmicrosoft_office_2019_for_64-bit_editions
msrcmicrosoft_office_2019_for_mac
msrcmicrosoft_office_online_server

Detection & IOCsextracted from sources · hover to see the quote

  • Attack vector requires a user to open a specially crafted Excel file; monitor for unexpected Excel file opens originating from email attachments or web downloads
  • Preview Pane is NOT an attack vector; exploitation requires full file open interaction — tune detections accordingly to focus on file-open events rather than preview events
  • ·Exploitation likelihood is rated 'Less Likely' for both latest and older software releases, and the vulnerability has not been publicly disclosed or exploited in the wild as of the advisory date

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.