CVE-2021-42293
published 2021-12-15CVE-2021-42293: Microsoft Jet Red Database Engine and Access Connectivity Engine Elevation of Privilege Vulnerability
PriorityP334medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
2.83%
85.0th percentile
Microsoft Jet Red Database Engine and Access Connectivity Engine Elevation of Privilege Vulnerability
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_365_apps_for_enterprise | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_2013_service_pack_1 | >= 15.0.0 < 15.0.5407.1000 | 15.0.5407.1000 |
| microsoft | microsoft_office_2016 | >= 16.0.0 < 16.0.5254.1000 | 16.0.5254.1000 |
| microsoft | microsoft_office_2019 | >= 19.0.0 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_ltsc_2021 | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office_long_term_servicing_channel | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_32-bit_systems | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_64-bit_systems | — | — |
| msrc | microsoft_office_2013_rt_service_pack_1 | — | — |
| msrc | microsoft_office_2013_service_pack_1 | — | — |
| msrc | microsoft_office_2016 | — | — |
| msrc | microsoft_office_2019_for_32-bit_editions | — | — |
| msrc | microsoft_office_2019_for_64-bit_editions | — | — |
| msrc | microsoft_office_ltsc_2021_for_32-bit_editions | — | — |
| msrc | microsoft_office_ltsc_2021_for_64-bit_editions | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_msrc6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Jet Red Database Engine and Access Connectivity Engine Elevation of Privilege Vulnerability
vendor_msrc·2021-12-14·CVSS 6.5
CVE-2021-42293 [MEDIUM] Microsoft Jet Red Database Engine and Access Connectivity Engine Elevation of Privilege Vulnerability
Microsoft Jet Red Database Engine and Access Connectivity Engine Elevation of Privilege Vulnerability
FAQ: Is the Preview Pane an attack vector for this vulnerability?
No, the Preview Pane is not an attack vector.
Microsoft Office Access: Microsoft Office Access
Microsoft: Microsoft
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Remediation: Click to Run
Reference: https://www.microsoft.com/downloads/details.aspx?familyid=c5738e86-427e-4284-9f69-b77eb2b33e73
Reference: https://support.microsoft.com/help/5002099
Reference: https://www.microsoft.com/downloads/details.aspx?familyid=ad2aebaf-7775-465c-8af4-7be5beeccc55
Reference: https://support.
GHSA
GHSA-pv66-8g6m-55pg: Microsoft Jet Red Database Engine and Access Connectivity Engine Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-02-11
CVE-2021-42293 [HIGH] CWE-269 GHSA-pv66-8g6m-55pg: Microsoft Jet Red Database Engine and Access Connectivity Engine Elevation of Privilege Vulnerability
Microsoft Jet Red Database Engine and Access Connectivity Engine Elevation of Privilege Vulnerability
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-12-15
Published