CVE-2021-42293

Severity
6.5MEDIUM
EPSS
3.0%
top 13.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 15
Latest updateFeb 11

Description

Microsoft Jet Red Database Engine and Access Connectivity Engine Elevation of Privilege Vulnerability

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages6 packages

CVEListV5microsoft/microsoft_office_201616.0.016.0.5254.1000
CVEListV5microsoft/microsoft_office_201919.0.0https://aka.ms/OfficeSecurityReleases
CVEListV5microsoft/microsoft_office_ltsc_202116.0.1https://aka.ms/OfficeSecurityReleases
CVEListV5microsoft/microsoft_365_apps_for_enterprise16.0.1https://aka.ms/OfficeSecurityReleases
CVEListV5microsoft/microsoft_office_2013_service_pack_115.0.015.0.5407.1000

Patches

🔴Vulnerability Details

2
GHSA
GHSA-pv66-8g6m-55pg: Microsoft Jet Red Database Engine and Access Connectivity Engine Elevation of Privilege Vulnerability2022-02-11
CVEList
Microsoft Jet Red Database Engine and Access Connectivity Engine Elevation of Privilege Vulnerability2021-12-15

📋Vendor Advisories

1
Microsoft
Microsoft Jet Red Database Engine and Access Connectivity Engine Elevation of Privilege Vulnerability2021-12-14