KLA12175
Multiple vulnerabilities in Microsoft Office

Обновлено: 22/06/2021
Дата обнаружения
11/05/2021
Уровень угрозы
High
Описание

Multiple vulnerabilities were found in Microsoft Office. Malicious users can exploit these vulnerabilities to execute arbitrary code, spoof user interface, obtain sensitive information.

Below is a complete list of vulnerabilities:

  1. A remote code execution vulnerability in Microsoft SharePoint can be exploited remotely to execute arbitrary code.
  2. A spoofing vulnerability in Skype for Business and Lync can be exploited remotely to spoof user interface.
  3. A remote code execution vulnerability in Skype for Business and Lync can be exploited remotely to execute arbitrary code.
  4. An information disclosure vulnerability in Microsoft Office can be exploited remotely to obtain sensitive information.
  5. A remote code execution vulnerability in Microsoft Jet Red Database Engine and Access Connectivity Engine can be exploited remotely to execute arbitrary code.
  6. A spoofing vulnerability in Microsoft SharePoint can be exploited remotely to spoof user interface.
  7. A remote code execution vulnerability in Microsoft Office can be exploited remotely to execute arbitrary code.
  8. A remote code execution vulnerability in Microsoft Office Graphics can be exploited remotely to execute arbitrary code.
  9. A remote code execution vulnerability in Microsoft SharePoint Server can be exploited remotely to execute arbitrary code.
  10. An information disclosure vulnerability in Microsoft SharePoint Server can be exploited remotely to obtain sensitive information.
  11. An information disclosure vulnerability in Microsoft Excel can be exploited remotely to obtain sensitive information.
  12. An information disclosure vulnerability in Microsoft SharePoint can be exploited remotely to obtain sensitive information.
Пораженные продукты

Microsoft Office Online Server
Microsoft SharePoint Enterprise Server 2016
Microsoft Office Web Apps Server 2013 Service Pack 1
Microsoft Office 2013 Service Pack 1 (32-bit editions)
Microsoft Excel 2013 Service Pack 1 (32-bit editions)
Microsoft Office 2016 (64-bit edition)
Microsoft Office 2016 (32-bit edition)
Microsoft Office 2013 RT Service Pack 1
Microsoft Word 2016 (64-bit edition)
Microsoft Excel 2013 Service Pack 1 (64-bit editions)
Microsoft Word 2013 RT Service Pack 1
Skype for Business Server 2015 CU11
Microsoft Office 2019 for 32-bit editions
Microsoft Excel 2016 (64-bit edition)
Microsoft Word 2013 Service Pack 1 (64-bit editions)
Microsoft SharePoint Foundation 2013 Service Pack 1
Skype for Business Server 2019 CU5
Microsoft Office 2019 for Mac
Microsoft Excel 2013 RT Service Pack 1
Microsoft Word 2016 (32-bit edition)
Microsoft Office 2019 for 64-bit editions
Microsoft 365 Apps for Enterprise for 32-bit Systems
Microsoft Lync Server 2013 CU10
Microsoft Excel 2016 (32-bit edition)
Microsoft SharePoint Server 2019
Microsoft Office 2013 Service Pack 1 (64-bit editions)
Microsoft 365 Apps for Enterprise for 64-bit Systems
Microsoft Word 2013 Service Pack 1 (32-bit editions)

Решение

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Первичный источник обнаружения
CVE-2021-31181
CVE-2021-26421
CVE-2021-26422
CVE-2021-31178
CVE-2021-28455
CVE-2021-26418
CVE-2021-31179
CVE-2021-31180
CVE-2021-28478
CVE-2021-28474
CVE-2021-31172
CVE-2021-31177
CVE-2021-31173
CVE-2021-31176
CVE-2021-31174
CVE-2021-31175
CVE-2021-31171
Оказываемое влияние
?
ACE 
[?]

OSI 
[?]

SUI 
[?]
Связанные продукты
Microsoft Lync
Microsoft Office
Microsoft Excel
Microsoft Word
Microsoft Windows
Microsoft Windows Server
Microsoft Windows Server 2012
Microsoft Windows 8
Microsoft Windows 7
Microsoft Windows Server 2008
Windows RT
Microsoft Lync Server
Microsoft Windows 10
CVE-IDS
CVE-2021-284555.0Critical
CVE-2021-311816.5High
CVE-2021-264215.0Critical
CVE-2021-264225.0Critical
CVE-2021-311785.0Critical
CVE-2021-264185.0Critical
CVE-2021-311795.0Critical
CVE-2021-311805.0Critical
CVE-2021-284785.0Critical
CVE-2021-284745.0Critical
CVE-2021-311725.0Critical
CVE-2021-311775.0Critical
CVE-2021-311735.0Critical
CVE-2021-311765.0Critical
CVE-2021-311745.0Critical
CVE-2021-311755.0Critical
CVE-2021-311715.0Critical