ZeroHour

CVE-2021-27059

KEVmass

Remote Code Execution Vulnerability in Microsoft Office

CISA: Microsoft Office Remote Code Execution Vulnerability

CVSS 3.1
7.6 high
EPSS
6%p93
Published
()
KEV added
AI analysis

CVE-2021-27059 is a remote code execution vulnerability in Microsoft Office. Per the CVSS vector (AV:N/AC:H/PR:H/UI:R/S:C), exploitation requires user interaction — typically the user opening crafted content — and involves high attack complexity with a scope change, meaning the attack crosses a security boundary. A successful attacker gains the ability to execute code in the context of the affected Office user. Microsoft Office, with Office 2016 explicitly listed, is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, confirming exploitation in the wild, though no public proof-of-concept is known, ransomware association is unknown, and EPSS estimates roughly a 6% probability of exploitation in the next 30 days (93rd percentile).

What to do: Apply Microsoft's current security updates for Office per vendor instructions across all affected installations, prioritizing Office 2016 deployments, and verify that updated builds are in place on user endpoints; note the CISA KEV listing imposes a federal patching deadline. Until patched, caution users against opening untrusted documents and monitor for suspicious activity following Office application launches. No public proof-of-concept is known, but in-the-wild exploitation is confirmed, so treat patching as urgent.

Affected
Microsoft Office
microsoft Office 2016
Estimated exposure
masshundreds of millions of users worldwide (Office is the dominant desktop productivity suite, with Office 2016 alone deployed on tens of millions of seats) — Office's enormous commercial and consumer install base and dominant productivity-suite market share put plausible exposure in the hundreds of millions of users, and the flaw is scoped by CISA to Office broadly rather than a niche component.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Office Remote Code Execution Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Office
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
office, office 2016
Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.