KLA12189
Multiple vulnerabilities in Microsoft Office

Updated: 06/09/2021
Detect date
?
05/11/2021
Severity
?
High
Description

Multiple vulnerabilities were found in Microsoft Office. Malicious users can exploit these vulnerabilities to execute arbitrary code, spoof user interface, obtain sensitive information.

Below is a complete list of vulnerabilities:

  1. A remote code execution vulnerability in Microsoft SharePoint can be exploited remotely to execute arbitrary code.
  2. A spoofing vulnerability in Skype for Business and Lync can be exploited remotely to spoof user interface.
  3. A remote code execution vulnerability in Skype for Business and Lync can be exploited remotely to execute arbitrary code.
  4. An information disclosure vulnerability in Microsoft Office can be exploited remotely to obtain sensitive information.
  5. A remote code execution vulnerability in Microsoft Jet Red Database Engine and Access Connectivity Engine can be exploited remotely to execute arbitrary code.
  6. A spoofing vulnerability in Microsoft SharePoint can be exploited remotely to spoof user interface.
  7. A remote code execution vulnerability in Microsoft Office can be exploited remotely to execute arbitrary code.
  8. A remote code execution vulnerability in Microsoft Office Graphics can be exploited remotely to execute arbitrary code.
  9. A remote code execution vulnerability in Microsoft SharePoint Server can be exploited remotely to execute arbitrary code.
  10. An information disclosure vulnerability in Microsoft SharePoint Server can be exploited remotely to obtain sensitive information.
  11. An information disclosure vulnerability in Microsoft Excel can be exploited remotely to obtain sensitive information.
  12. An information disclosure vulnerability in Microsoft SharePoint can be exploited remotely to obtain sensitive information.
Affected products

Microsoft Office Online Server
Microsoft SharePoint Enterprise Server 2016
Microsoft Office Web Apps Server 2013 Service Pack 1
Microsoft Office 2013 Service Pack 1 (32-bit editions)
Microsoft Excel 2013 Service Pack 1 (32-bit editions)
Microsoft Office 2016 (64-bit edition)
Microsoft Office 2016 (32-bit edition)
Microsoft Office 2013 RT Service Pack 1
Microsoft Word 2016 (64-bit edition)
Microsoft Excel 2013 Service Pack 1 (64-bit editions)
Microsoft Word 2013 RT Service Pack 1
Skype for Business Server 2015 CU11
Microsoft Office 2019 for 32-bit editions
Microsoft Excel 2016 (64-bit edition)
Microsoft Word 2013 Service Pack 1 (64-bit editions)
Microsoft SharePoint Foundation 2013 Service Pack 1
Skype for Business Server 2019 CU5
Microsoft Office 2019 for Mac
Microsoft Excel 2013 RT Service Pack 1
Microsoft Word 2016 (32-bit edition)
Microsoft Office 2019 for 64-bit editions
Microsoft 365 Apps for Enterprise for 32-bit Systems
Microsoft Lync Server 2013 CU10
Microsoft Excel 2016 (32-bit edition)
Microsoft SharePoint Server 2019
Microsoft Office 2013 Service Pack 1 (64-bit editions)
Microsoft 365 Apps for Enterprise for 64-bit Systems
Microsoft Word 2013 Service Pack 1 (32-bit editions)

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Original advisories

CVE-2021-31181
CVE-2021-26421
CVE-2021-26422
CVE-2021-31178
CVE-2021-28455
CVE-2021-26418
CVE-2021-31179
CVE-2021-31180
CVE-2021-28478
CVE-2021-28474
CVE-2021-31172
CVE-2021-31177
CVE-2021-31173
CVE-2021-31176
CVE-2021-31174
CVE-2021-31175
CVE-2021-31171

Impacts
?
ACE 
[?]

OSI 
[?]

SUI 
[?]
Related products
Microsoft Lync
Microsoft Office
Microsoft Excel
Microsoft Word
Microsoft Windows
Microsoft Windows Server
Microsoft Windows Server 2012
Microsoft Windows 8
Microsoft Windows 7
Microsoft Windows Server 2008
Windows RT
Microsoft Lync Server
Microsoft Windows 10
CVE-IDS
?
CVE-2021-284555.0Critical
CVE-2021-311815.0Critical
CVE-2021-264215.0Critical
CVE-2021-264225.0Critical
CVE-2021-311785.0Critical
CVE-2021-264185.0Critical
CVE-2021-311795.0Critical
CVE-2021-311805.0Critical
CVE-2021-284785.0Critical
CVE-2021-284745.0Critical
CVE-2021-311725.0Critical
CVE-2021-311775.0Critical
CVE-2021-311735.0Critical
CVE-2021-311765.0Critical
CVE-2021-311745.0Critical
CVE-2021-311755.0Critical
CVE-2021-311715.0Critical
KB list

5001914
5001931
5001919
5001917
4493197
5003729
4464542
5001920
5001927
5001923
4493206
5001918
5001916
5001928
5001936
5001925
5001935
4504711
4484527

Find out the statistics of the vulnerabilities spreading in your region