CVE-2021-38658
published 2021-09-15CVE-2021-38658: Microsoft Office Graphics Remote Code Execution Vulnerability
PriorityP343high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
4.88%
91.1th percentile
Microsoft Office Graphics Remote Code Execution Vulnerability
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_office_2013_service_pack_1 | >= 15.0.0 < 5381.1000 | 5381.1000 |
| microsoft | microsoft_office_2016 | >= 16.0.0 < 5215.1000 | 5215.1000 |
| microsoft | microsoft_office_2019 | >= 19.0.0 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| msrc | microsoft_office_2013_rt_service_pack_1 | — | — |
| msrc | microsoft_office_2013_service_pack_1 | — | — |
| msrc | microsoft_office_2016 | — | — |
| msrc | microsoft_office_2019_for_32-bit_editions | — | — |
| msrc | microsoft_office_2019_for_64-bit_editions | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7g65-rwp5-vwpp: Microsoft Office Graphics Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-38658
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2021-38660 [HIGH] GHSA-7g65-rwp5-vwpp: Microsoft Office Graphics Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-38658
Microsoft Office Graphics Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-38658.
GHSA
GHSA-2jvq-3rhr-97x9: Microsoft Office Graphics Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-38660
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2021-38658 [HIGH] CWE-843 GHSA-2jvq-3rhr-97x9: Microsoft Office Graphics Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-38660
Microsoft Office Graphics Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-38660.
Microsoft
Microsoft Office Graphics Remote Code Execution Vulnerability
vendor_msrc·2021-09-14·CVSS 7.8
CVE-2021-38658 [HIGH] Microsoft Office Graphics Remote Code Execution Vulnerability
Microsoft Office Graphics Remote Code Execution Vulnerability
FAQ: Is the Preview Pane an attack vector for this vulnerability?
No, the Preview Pane is not an attack vector.
Microsoft Office: Microsoft Office
Microsoft: Microsoft
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Remediation: Click to Run
Reference: https://www.microsoft.com/downloads/details.aspx?familyid=1d080be7-9ed1-49e1-b7c4-45976a6dd63b
Reference: https://www.microsoft.com/downloads/details.aspx?familyid=fdb96ab7-c567-48d9-bf4b-5dbcfbf99975
Reference: https://www.microsoft.com/downloads/details.aspx?familyid=b3e5b65a-d319-459e-acec-91ae93dddc6e
Reference: https://www.microso
No detection rules found.
No public exploits indexed.
Qualys
Microsoft and Adobe Patch Tuesday (September 2021) – Microsoft 60 Vulnerabilities with 3 Critical, Adobe 61 Vulnerabilities
blogs_qualys·2021-09-14·CVSS 8.1
CVE-2021-40444 [HIGH] Microsoft and Adobe Patch Tuesday (September 2021) – Microsoft 60 Vulnerabilities with 3 Critical, Adobe 61 Vulnerabilities
## Microsoft Patch Tuesday – September 2021
Microsoft patched 60 vulnerabilities in their September 2021 Patch Tuesday release, and an additional 26 CVEs since September 1st. Among the 60 released in the September Patch Tuesday, 3 of them are rated as critical severity, one as moderate, and 56 as important.
## Critical Microsoft Vulnerabilities Patched
CVE-2021-40444 – Microsoft MSHTML Remote Code Execution Vulnerability
This vulnerability has been publicly disclosed and is known to be exploited. The vulnerability allows for remote code execution via MSHTML, a component used by Internet Explorer and Office. Microsoft also released a workaround to show how users can disable ActiveX controls in IE. The vendor has assigned a CVSSv3 base score of 8.8. It should be prioritized for patching.
Trendmicro
September Patch Tuesday: 66 Bulletins, Only 3 Critical
blogs_trendmicro·2021-09-14·CVSS 8.1
[HIGH] September Patch Tuesday: 66 Bulletins, Only 3 Critical
Exploits & Vulnerabilities
# September Patch Tuesday: 66 Bulletins, Only 3 Critical
The September 2021 Patch Tuesday cycle is relatively good news for system administrators with only 66 total bulletins. Perhaps more significantly, only three of these were Critical bulletins.
By: Trend Micro
2021/09/14
Read time: ( words)
Save to Folio
The September 2021 Patch Tuesday cycle is relatively good news for system administrators with only 66 total bulletins. Perhaps more significantly, only three of these were Critical bulletins. Eleven of these bulletins fixed vulnerabilities that were disclosed to Microsoft via the Zero Day Initiative. Overall, the month offers system administrators a chance to catch up on other necessary tasks.
Only 3 Critical Patches for September
As mentioned previou
2021-09-15
Published