ZeroHour

CVE-2021-38646

KEV ransomwaremass

RCE in Microsoft Office Access Connectivity Engine exploited by ransomware

CISA: Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability

CVSS 3.1
7.8 high
EPSS
8%p94
Published
()
KEV added
AI analysis

CVE-2021-38646 is a remote code execution vulnerability in the Microsoft Office Access Connectivity Engine (ACE), the database engine bundled with Office that opens and processes database files. It is triggered locally (CVSS:3.1 AV:L, user interaction required, no privileges needed) when a user is persuaded to open a specially crafted file — typically a database or Office file that invokes the ACE engine — on an affected Office installation. Successful exploitation lets an attacker execute arbitrary code in the context of the signed-in user, providing initial access that has been chained into ransomware deployments, which CISA confirms as known ransomware use. Users of Microsoft Office 2016, Office 2019, and Microsoft 365 Apps are affected according to CISA's listing. The flaw is known to be exploited in the wild — it was added to CISA's KEV on 2022-03-28 — while no public proof-of-concept is available, and EPSS assigns an 8% probability of exploitation within 30 days (94th percentile).

What to do: Apply Microsoft's security updates for CVE-2021-38646 to Microsoft 365 Apps, Office 2016, and Office 2019 per vendor instructions, and verify remediated builds across your fleet, prioritizing endpoints where users open untrusted files or where Microsoft Access is installed. Until patched, caution users against opening untrusted database/Office files, since exploitation requires user interaction. There is no public PoC, but confirmed ransomware use and the CISA KEV listing make this a priority patch within KEV remediation timelines.

Affected
Microsoft 365 Apps
Microsoft Office (generic CPE listing)
Microsoft Office 2016
Microsoft Office 2019
Estimated exposure
mass≈ hundreds of millions of Office installations (Office 2016/2019 and Microsoft 365 Apps are among the most widely deployed Office editions; the currently… — Office runs on well over a billion devices worldwide and Office 2016/2019/Microsoft 365 Apps held dominant installed shares at the time of disclosure, so the plausibly affected pre-patch population is safely in the hundreds of millions of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Office
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
365 apps, office, office 2016, office 2019
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news