CVE-2021-38646
KEV ransomwaremassRCE in Microsoft Office Access Connectivity Engine exploited by ransomware
CISA: Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
CVE-2021-38646 is a remote code execution vulnerability in the Microsoft Office Access Connectivity Engine (ACE), the database engine bundled with Office that opens and processes database files. It is triggered locally (CVSS:3.1 AV:L, user interaction required, no privileges needed) when a user is persuaded to open a specially crafted file — typically a database or Office file that invokes the ACE engine — on an affected Office installation. Successful exploitation lets an attacker execute arbitrary code in the context of the signed-in user, providing initial access that has been chained into ransomware deployments, which CISA confirms as known ransomware use. Users of Microsoft Office 2016, Office 2019, and Microsoft 365 Apps are affected according to CISA's listing. The flaw is known to be exploited in the wild — it was added to CISA's KEV on 2022-03-28 — while no public proof-of-concept is available, and EPSS assigns an 8% probability of exploitation within 30 days (94th percentile).
What to do: Apply Microsoft's security updates for CVE-2021-38646 to Microsoft 365 Apps, Office 2016, and Office 2019 per vendor instructions, and verify remediated builds across your fleet, prioritizing endpoints where users open untrusted files or where Microsoft Access is installed. Until patched, caution users against opening untrusted database/Office files, since exploitation requires user interaction. There is no public PoC, but confirmed ransomware use and the CISA KEV listing make this a priority patch within KEV remediation timelines.
| Microsoft 365 Apps | — |
| Microsoft Office (generic CPE listing) | — |
| Microsoft Office 2016 | — |
| Microsoft Office 2019 | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
- Affected
- Microsoft Office
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- microsoft
- Products
- 365 apps, office, office 2016, office 2019
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H