CVE-2021-38646
published 2021-09-15CVE-2021-38646: Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
PriorityP184high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2022-04-18
Exploited in the wild
EPSS
4.40%
90.3th percentile
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_365_apps_for_enterprise | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_2013_service_pack_1 | >= 15.0.0 < 5381.1000 | 5381.1000 |
| microsoft | microsoft_office_2016 | >= 16.0.0 < 5215.1000 | 5215.1000 |
| microsoft | microsoft_office_2019 | >= 19.0.0 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_32-bit_systems | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_64-bit_systems | — | — |
| msrc | microsoft_office_2013_rt_service_pack_1 | — | — |
| msrc | microsoft_office_2013_service_pack_1 | — | — |
| msrc | microsoft_office_2016 | — | — |
| msrc | microsoft_office_2019_for_32-bit_editions | — | — |
| msrc | microsoft_office_2019_for_64-bit_editions | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Preview Pane is NOT an attack vector; user interaction (opening a malicious Access file) is required for exploitation ↗
- →Affected component is Microsoft Office Access Connectivity Engine (ACE); monitor for suspicious Access database file opens or ACE engine process activity ↗
- ·Exploitation likelihood is rated 'Less Likely' for both latest and older software releases as of advisory publication; however, CISA added this to the Known Exploited Vulnerabilities catalog with a remediation due date, indicating elevated real-world risk ↗
- ·No public exploit or active exploitation confirmed at time of Microsoft advisory, but CISA mandated remediation by 2022-04-18 ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-846x-h43v-68x9: Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
ghsa_unreviewed·2022-05-24
CVE-2021-38646 [HIGH] CWE-119 GHSA-846x-h43v-68x9: Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
VulnCheck
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
vulncheck·2021·CVSS 7.8
CVE-2021-38646 [HIGH] Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
Microsoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution.
Affected: Microsoft Office
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://static.tenable.com/marketing/whitepapers/Whitepaper-Ransomware_Ecosystem.pdf
Remediation Due: 2022-04-18
CISA
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
cisa·2022-03-28·CVSS 7.8
CVE-2021-38646 [HIGH] Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
Vulnerability: Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
Affected: Microsoft Office
Microsoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-38646
Remediation Due Date: 2022-04-18
Microsoft
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
vendor_msrc·2021-09-14·CVSS 7.8
CVE-2021-38646 [HIGH] Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
FAQ: Is the Preview Pane an attack vector for this vulnerability?
No, the Preview Pane is not an attack vector.
Microsoft Office Access: Microsoft Office Access
Microsoft: Microsoft
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Remediation: Click to Run
Reference: https://www.microsoft.com/downloads/details.aspx?familyid=5fc41c1d-ca0d-4250-907e-1e9e55498c05
Reference: https://www.microsoft.com/downloads/details.aspx?familyid=fa7826f4-771f-4c30-9a8a-a663d4f9d098
Reference: https://www.microsoft.com/downloads/details.aspx?familyid=41f28314-646f-4e17-829e-2bfdd3e94f56
No detection rules found.
No public exploits indexed.
2021-09-15
Published
2022-03-28
Added to CISA KEV
Exploited in the wild