CVE-2021-38654
published 2021-09-15CVE-2021-38654: Microsoft Office Visio Remote Code Execution Vulnerability
PriorityP343high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
4.86%
91.0th percentile
Microsoft Office Visio Remote Code Execution Vulnerability
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_365_apps_for_enterprise | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_2019 | >= 19.0.0 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | office | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_32-bit_systems | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_64-bit_systems | — | — |
| msrc | microsoft_office_2019_for_32-bit_editions | — | — |
| msrc | microsoft_office_2019_for_64-bit_editions | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mr75-cw8v-jgmf: Microsoft Office Visio Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-38654
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2021-38653 [HIGH] CWE-787 GHSA-mr75-cw8v-jgmf: Microsoft Office Visio Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-38654
Microsoft Office Visio Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-38654.
GHSA
GHSA-33p4-33f5-c62r: Microsoft Office Visio Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-38653
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2021-38654 [HIGH] CWE-129 GHSA-33p4-33f5-c62r: Microsoft Office Visio Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-38653
Microsoft Office Visio Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-38653.
Microsoft
Microsoft Office Visio Remote Code Execution Vulnerability
vendor_msrc·2021-09-14·CVSS 7.8
CVE-2021-38654 [HIGH] Microsoft Office Visio Remote Code Execution Vulnerability
Microsoft Office Visio Remote Code Execution Vulnerability
FAQ: Is the Preview Pane an attack vector for this vulnerability?
No, the Preview Pane is not an attack vector.
Microsoft Office Visio: Microsoft Office Visio
Microsoft: Microsoft
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Remediation: Click to Run
No detection rules found.
No public exploits indexed.
Qualys
Microsoft and Adobe Patch Tuesday (September 2021) – Microsoft 60 Vulnerabilities with 3 Critical, Adobe 61 Vulnerabilities
blogs_qualys·2021-09-14·CVSS 8.1
CVE-2021-40444 [HIGH] Microsoft and Adobe Patch Tuesday (September 2021) – Microsoft 60 Vulnerabilities with 3 Critical, Adobe 61 Vulnerabilities
## Microsoft Patch Tuesday – September 2021
Microsoft patched 60 vulnerabilities in their September 2021 Patch Tuesday release, and an additional 26 CVEs since September 1st. Among the 60 released in the September Patch Tuesday, 3 of them are rated as critical severity, one as moderate, and 56 as important.
## Critical Microsoft Vulnerabilities Patched
CVE-2021-40444 – Microsoft MSHTML Remote Code Execution Vulnerability
This vulnerability has been publicly disclosed and is known to be exploited. The vulnerability allows for remote code execution via MSHTML, a component used by Internet Explorer and Office. Microsoft also released a workaround to show how users can disable ActiveX controls in IE. The vendor has assigned a CVSSv3 base score of 8.8. It should be prioritized for patching.
Trendmicro
September Patch Tuesday: 66 Bulletins, Only 3 Critical
blogs_trendmicro·2021-09-14·CVSS 8.1
[HIGH] September Patch Tuesday: 66 Bulletins, Only 3 Critical
Exploits & Vulnerabilities
# September Patch Tuesday: 66 Bulletins, Only 3 Critical
The September 2021 Patch Tuesday cycle is relatively good news for system administrators with only 66 total bulletins. Perhaps more significantly, only three of these were Critical bulletins.
By: Trend Micro
2021/09/14
Read time: ( words)
Save to Folio
The September 2021 Patch Tuesday cycle is relatively good news for system administrators with only 66 total bulletins. Perhaps more significantly, only three of these were Critical bulletins. Eleven of these bulletins fixed vulnerabilities that were disclosed to Microsoft via the Zero Day Initiative. Overall, the month offers system administrators a chance to catch up on other necessary tasks.
Only 3 Critical Patches for September
As mentioned previou
2021-09-15
Published