CVE-2021-40474
published 2021-10-13CVE-2021-40474: Microsoft Excel Remote Code Execution Vulnerability
PriorityP341high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
2.19%
80.5th percentile
Microsoft Excel Remote Code Execution Vulnerability
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | excel | — | — |
| microsoft | excel | — | — |
| microsoft | microsoft_365_apps_for_enterprise | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_excel_2013_service_pack_1 | >= 15.0.0.0 < 15.0.5389.1000 | 15.0.5389.1000 |
| microsoft | microsoft_excel_2016 | >= 16.0.0.0 < 16.0.5227.1000 | 16.0.5227.1000 |
| microsoft | microsoft_office_2019 | >= 19.0.0 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_2019_for_mac | >= 16.0.0 < 16.54.21101001 | 16.54.21101001 |
| microsoft | microsoft_office_ltsc_2021 | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_ltsc_for_mac_2021 | >= 16.0.1 < 16.54.21101001 | 16.54.21101001 |
| microsoft | microsoft_office_online_server | >= 16.0.1 < 16.0.10379.20000 | 16.0.10379.20000 |
| microsoft | microsoft_office_web_apps_server_2013_service_pack_1 | >= 15.0.1 < 15.0.5389.1000 | 15.0.5389.1000 |
| microsoft | office | — | — |
| microsoft | office_long_term_servicing_channel | — | — |
| microsoft | office_web_apps_server | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_32-bit_systems | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_64-bit_systems | — | — |
| msrc | microsoft_excel_2013_rt_service_pack_1 | — | — |
| msrc | microsoft_excel_2013_service_pack_1 | — | — |
| msrc | microsoft_excel_2016 | — | — |
| msrc | microsoft_office_2019_for_32-bit_editions | — | — |
| msrc | microsoft_office_2019_for_64-bit_editions | — | — |
| msrc | microsoft_office_2019_for_mac | — | — |
| msrc | microsoft_office_ltsc_2021_for_32-bit_editions | — | — |
| msrc | microsoft_office_ltsc_2021_for_64-bit_editions | — | — |
| msrc | microsoft_office_ltsc_for_mac_2021 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Excel Remote Code Execution Vulnerability
vendor_msrc·2021-10-12·CVSS 7.8
CVE-2021-40474 [HIGH] Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
FAQ: Is the Preview Pane an attack vector for this vulnerability?
No, the Preview Pane is not an attack vector.
Microsoft Office Excel: Microsoft Office Excel
Microsoft: Microsoft
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Remediation: Click to Run
Remediation: Release Notes
Reference: https://go.microsoft.com/fwlink/p/?linkid=831049
Reference: https://www.microsoft.com/downloads/details.aspx?familyid=170d4991-51ce-42cf-94bf-525555b3a90a
Reference: https://www.microsoft.com/downloads/details.aspx?familyid=5cbdb0ac-5257-4d9d-8e70-8aaeaaccf57d
Reference: https://www.microsoft.com/downloads
GHSA
GHSA-5fv8-8523-rqc9: Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-40473, CVE-2021-40474, CVE-2021-40479, CVE-2021-40485
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2021-40471 [HIGH] GHSA-5fv8-8523-rqc9: Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-40473, CVE-2021-40474, CVE-2021-40479, CVE-2021-40485
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-40473, CVE-2021-40474, CVE-2021-40479, CVE-2021-40485.
GHSA
GHSA-jh57-6wxr-9h8f: Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-40471, CVE-2021-40473, CVE-2021-40474, CVE-2021-40479
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2021-40485 [HIGH] CWE-94 GHSA-jh57-6wxr-9h8f: Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-40471, CVE-2021-40473, CVE-2021-40474, CVE-2021-40479
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-40471, CVE-2021-40473, CVE-2021-40474, CVE-2021-40479.
GHSA
GHSA-hm57-386j-q92j: Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-40471, CVE-2021-40473, CVE-2021-40479, CVE-2021-40485
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2021-40474 [HIGH] GHSA-hm57-386j-q92j: Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-40471, CVE-2021-40473, CVE-2021-40479, CVE-2021-40485
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-40471, CVE-2021-40473, CVE-2021-40479, CVE-2021-40485.
GHSA
GHSA-fqvw-qcgx-mv48: Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-40471, CVE-2021-40473, CVE-2021-40474, CVE-2021-40485
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2021-40479 [HIGH] GHSA-fqvw-qcgx-mv48: Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-40471, CVE-2021-40473, CVE-2021-40474, CVE-2021-40485
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-40471, CVE-2021-40473, CVE-2021-40474, CVE-2021-40485.
GHSA
GHSA-25fm-hfr5-5989: Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-40471, CVE-2021-40474, CVE-2021-40479, CVE-2021-40485
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2021-40473 [HIGH] GHSA-25fm-hfr5-5989: Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-40471, CVE-2021-40474, CVE-2021-40479, CVE-2021-40485
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-40471, CVE-2021-40474, CVE-2021-40479, CVE-2021-40485.
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Use-after-free vulnerability in Microsoft Excel could lead to code execution
blogs_talos·2021-10-12·CVSS 7.8
[HIGH] Vulnerability Spotlight: Use-after-free vulnerability in Microsoft Excel could lead to code execution
## Vulnerability Spotlight: Use-after-free vulnerability in Microsoft Excel could lead to code execution
Marcin “Icewall” Noga of Cisco Talos discovered this vulnerability.
Cisco Talos recently discovered a use-after-free vulnerability in the ConditionalFormatting functionality of Microsoft Office Excel 2019 that could allow an attacker to execute arbitrary code on the victim machine.
Microsoft disclosed and patched this vulnerability in the popular spreadsheet creation and editing platform as part of its monthly security update. You can read more about Patch Tuesday here . TALOS-2021-1259 (CVE-2021-40474) could be exploited by an attacker if they tricked the target into opening a specially crafted Excel file. Proper heap grooming on the attacker’s part could give them full control of t
Talos
Microsoft Patch Tuesday for Oct. 2021 — Snort rules and prominent vulnerabilities
blogs_talos·2021-10-12·CVSS 8.8
[HIGH] Microsoft Patch Tuesday for Oct. 2021 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for Oct. 2021 — Snort rules and prominent vulnerabilities
By Jon Munshaw, with contributions from Asheer Malhotra.
Microsoft released its monthly security update Tuesday, disclosing 78 vulnerabilities in the company’s various software, hardware and firmware offerings.
This month’s release is particularly notable because there are only two critical vulnerabilities included, with the rest being important. This is the fewest number of critical vulnerabilities disclosed as part of a Patch Tuesday in at least a year.
CVE-2021-40461 is one of the critical vulnerabilities — a flaw in the Network Virtualization Service Provider that could allow an attacker to execute remote code on the target machine. This vulnerability has a severity rating of 9.9 out of a possible
Talos
Vulnerability Spotlight: Use-after-free vulnerability in Microsoft Excel could lead to code execution
blogs_talos·2021-10-12·CVSS 7.8
[HIGH] Vulnerability Spotlight: Use-after-free vulnerability in Microsoft Excel could lead to code execution
Marcin “Icewall” Noga of Cisco Talos discovered this vulnerability.
Cisco Talos recently discovered a use-after-free vulnerability in the ConditionalFormatting functionality of Microsoft Office Excel 2019 that could allow an attacker to execute arbitrary code on the victim machine.
Microsoft disclosed and patched this vulnerability in the popular spreadsheet creation and editing platform as part of its monthly security update. You can read more about Patch Tuesday here. TALOS-2021-1259 (CVE-2021-40474) could be exploited by an attacker if they tricked the target into opening a specially crafted Excel file. Proper heap grooming on the attacker’s part could give them full control of this use-after-free vulnerability and, as a result, could allow it to be turned into arbitrary code executio
Talos
Microsoft Patch Tuesday for Oct. 2021 — Snort rules and prominent vulnerabilities
blogs_talos·2021-10-12·CVSS 8.8
CVE-2021-40461 [HIGH] Microsoft Patch Tuesday for Oct. 2021 — Snort rules and prominent vulnerabilities
By Jon Munshaw, with contributions from Asheer Malhotra.
Microsoft released its monthly security update Tuesday, disclosing 78 vulnerabilities in the company’s various software, hardware and firmware offerings.
This month’s release is particularly notable because there are only two critical vulnerabilities included, with the rest being important. This is the fewest number of critical vulnerabilities disclosed as part of a Patch Tuesday in at least a year.
CVE-2021-40461 is one of the critical vulnerabilities — a flaw in the Network Virtualization Service Provider that could allow an attacker to execute remote code on the target machine. This vulnerability has a severity rating of 9.9 out of a possible 10, virtually the highest severity rating seen in Patch Tuesdays.
The other critical
2021-10-13
Published