CVE-2021-40486
published 2021-10-13CVE-2021-40486: Microsoft Word Remote Code Execution Vulnerability
PriorityP344high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
5.69%
92.1th percentile
Microsoft Word Remote Code Execution Vulnerability
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_office_2019 | >= 19.0.0 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_online_server | >= 16.0.1 < 16.0.10379.20000 | 16.0.10379.20000 |
| microsoft | microsoft_office_web_apps_server_2013_service_pack_1 | >= 15.0.1 < 15.0.5389.1000 | 15.0.5389.1000 |
| microsoft | microsoft_sharepoint_enterprise_server_2013_service_pack_1 | >= 15.0.0 < 15.0.5389.1000 | 15.0.5389.1000 |
| microsoft | microsoft_sharepoint_enterprise_server_2016 | >= 16.0.0 < 16.0.5227.1000 | 16.0.5227.1000 |
| microsoft | microsoft_sharepoint_server_2019 | >= 16.0.0 < 16.0.10379.20000 | 16.0.10379.20000 |
| microsoft | microsoft_word_2013_service_pack_1 | >= 15.0.1 < 15.0.5389.1000 | 15.0.5389.1000 |
| microsoft | microsoft_word_2016 | >= 16.0.1 < 16.0.5227.1000 | 16.0.5227.1000 |
| microsoft | office | — | — |
| microsoft | office_web_apps_server | — | — |
| microsoft | sharepoint_enterprise_server | — | — |
| microsoft | sharepoint_enterprise_server | — | — |
| microsoft | sharepoint_server | — | — |
| microsoft | word | — | — |
| microsoft | word | — | — |
| msrc | microsoft_office_2019_for_32-bit_editions | — | — |
| msrc | microsoft_office_2019_for_64-bit_editions | — | — |
| msrc | microsoft_office_online_server | — | — |
| msrc | microsoft_office_web_apps_server_2013_service_pack_1 | — | — |
| msrc | microsoft_sharepoint_enterprise_server_2013_service_pack_1 | — | — |
| msrc | microsoft_sharepoint_enterprise_server_2016 | — | — |
| msrc | microsoft_sharepoint_server_2019 | — | — |
| msrc | microsoft_word_2013_rt_service_pack_1 | — | — |
| msrc | microsoft_word_2013_service_pack_1 | — | — |
| msrc | microsoft_word_2016 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f354-fqf2-9hm4: Microsoft Word Remote Code Execution Vulnerability
ghsa_unreviewed·2022-05-24
CVE-2021-40486 [HIGH] GHSA-f354-fqf2-9hm4: Microsoft Word Remote Code Execution Vulnerability
Microsoft Word Remote Code Execution Vulnerability
Microsoft
Microsoft Word Remote Code Execution Vulnerability
vendor_msrc·2021-10-12·CVSS 7.8
CVE-2021-40486 [HIGH] Microsoft Word Remote Code Execution Vulnerability
Microsoft Word Remote Code Execution Vulnerability
FAQ: Is the Preview Pane an attack vector for this vulnerability?
Yes, the Preview Pane is an attack vector.
Microsoft Office Word: Microsoft Office Word
Microsoft: Microsoft
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://www.microsoft.com/downloads/details.aspx?familyid=dc08d7a5-c213-4842-8824-e43876d474a1
Reference: https://www.microsoft.com/downloads/details.aspx?familyid=483ed881-ac87-43a6-8861-e1a7704c46ab
Reference: https://www.microsoft.com/downloads/details.aspx?familyid=d7cfd04b-a35d-4a35-9df8-3e0ad3f49a99
Reference: https://www.microsoft.com/downloads/details.aspx?f
No detection rules found.
No public exploits indexed.
Trendmicro
October Patch Tuesday: 3 Critical Bulletins Among 71
blogs_trendmicro·2021-10-13·CVSS 8.0
[HIGH] October Patch Tuesday: 3 Critical Bulletins Among 71
Exploits & Vulnerabilities
# October Patch Tuesday: 3 Critical Bulletins Among 71
The October Patch Tuesday maintains the relatively peaceful streak from previous months with only 3 bulletins rated as Critical among 71 new vulnerabilities.
By: Trend Micro
2021/10/13
Read time: ( words)
Save to Folio
The October 2021 Patch Tuesday continues the quiet streak observed for the months of August and September. Out of 71 bulletins, only three were rated Critical this month. The list also included a fix for four publicly known vulnerabilities. Of the fixed vulnerabilities, 11 were disclosed via the Zero Day Initiative.
Three Critical patches and other notable vulnerabilities
Only three patches were rated Critical this month. Two of them were remote code execution (RCE) vulnerabilities (CVE
Crowdstrike
October 2021 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] October 2021 Patch Tuesday: Updates and Analysis
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
2021-10-13
Published