⚠ Actively exploited in ransomware campaigns
This vulnerability is on the CISA Known Exploited Vulnerabilities list and has been used in known ransomware attacks. CISA required action: Apply updates per vendor instructions.. Due date: 2022-04-18.

CVE-2021-38646

CWE-119Buffer Overflow6 documents6 sources
Severity
7.8HIGH
EPSS
50.9%
top 2.13%
CISA KEV
KEVRansomware
Added 2022-03-28
Due 2022-04-18
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedSep 15
KEV addedMar 28
KEV dueApr 18
Latest updateMay 24
CISA Required Action: Apply updates per vendor instructions.

Description

Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages5 packages

CVEListV5microsoft/microsoft_office_201616.0.05215.1000
CVEListV5microsoft/microsoft_office_201919.0.0https://aka.ms/OfficeSecurityReleases
CVEListV5microsoft/microsoft_office_2013_service_pack_115.0.05381.1000
NVDmicrosoft/office2013, 2016, 2019+2
CVEListV5microsoft/microsoft_365_apps_for_enterprise16.0.1https://aka.ms/OfficeSecurityReleases

Patches

🔴Vulnerability Details

3
GHSA
GHSA-846x-h43v-68x9: Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability2022-05-24
CVEList
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability2021-09-15
VulnCheck
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability2021

📋Vendor Advisories

2
CISA
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability2022-03-28
Microsoft
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability2021-09-14
CVE-2021-38646 (HIGH CVSS 7.8) | Microsoft Office Access Connectivit | cvebase.io