KLA12201
Multiple vulnerabilities in Microsoft Office

Обновлено: 22/06/2021
Дата обнаружения
08/06/2021
Уровень угрозы
Critical
Описание

Multiple vulnerabilities were found in Microsoft Office. Malicious users can exploit these vulnerabilities to execute arbitrary code, spoof user interface, obtain sensitive information.

Below is a complete list of vulnerabilities:

  1. A remote code execution vulnerability in Microsoft Office Graphics can be exploited remotely to execute arbitrary code.
  2. A remote code execution vulnerability in Microsoft Outlook can be exploited remotely to execute arbitrary code.
  3. A remote code execution vulnerability in Microsoft SharePoint Server can be exploited remotely to execute arbitrary code.
  4. A spoofing vulnerability in Microsoft SharePoint Server can be exploited remotely to spoof user interface.
  5. A remote code execution vulnerability in Microsoft Excel can be exploited remotely to execute arbitrary code.
  6. An information disclosure vulnerability in Microsoft SharePoint Server can be exploited remotely to obtain sensitive information.
Пораженные продукты

Microsoft SharePoint Enterprise Server 2016
Microsoft Office Web Apps Server 2013 Service Pack 1
Microsoft Office 2013 Service Pack 1 (32-bit editions)
Microsoft Excel 2013 Service Pack 1 (32-bit editions)
Microsoft Office 2016 (64-bit edition)
Microsoft Office 2016 (32-bit edition)
Microsoft Outlook 2013 Service Pack 1 (64-bit editions)
Microsoft Outlook 2016 (64-bit edition)
Microsoft Outlook 2013 Service Pack 1 (32-bit editions)
Microsoft Office 2013 RT Service Pack 1
Microsoft Excel 2013 Service Pack 1 (64-bit editions)
Microsoft Office 2019 for 32-bit editions
Microsoft Excel 2016 (64-bit edition)
Microsoft SharePoint Foundation 2013 Service Pack 1
Microsoft Office 2019 for Mac
Microsoft Excel 2013 RT Service Pack 1
Microsoft Outlook 2016 (32-bit edition)
Microsoft Office 2019 for 64-bit editions
Microsoft 365 Apps for Enterprise for 32-bit Systems
Microsoft Excel 2016 (32-bit edition)
Microsoft SharePoint Enterprise Server 2013 Service Pack 1
Microsoft SharePoint Server 2019
Microsoft Office 2013 Service Pack 1 (64-bit editions)
Microsoft Outlook 2013 RT Service Pack 1
Microsoft 365 Apps for Enterprise for 64-bit Systems
Office Online Server

Решение

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Первичный источник обнаружения
CVE-2021-31940
CVE-2021-31949
CVE-2021-26420
CVE-2021-31948
CVE-2021-31966
CVE-2021-31939
CVE-2021-31965
CVE-2021-31941
CVE-2021-31963
CVE-2021-31964
CVE-2021-31950
Оказываемое влияние
?
ACE 
[?]

OSI 
[?]

SUI 
[?]
Связанные продукты
Microsoft Office
Microsoft Outlook
Microsoft Excel
CVE-IDS