Microsoft Office是美国微软(Microsoft)公司的一款办公软件套件产品。该产品常用组件包括Word、Excel、Access、Powerpoint、FrontPage等。 Microsoft Office Excel存在代码注入漏洞。以下产品和版本受到影响:Microsoft Office 2019 for 64-bit editions,Microsoft Office 2019 for Mac,Microsoft Office Online Server,Microsoft 365
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Microsoft | Microsoft 365 Apps for Enterprise | 16.0.1< https://aka.ms/OfficeSecurityReleases |
affected |
| Microsoft | Microsoft Excel 2013 Service Pack 1 | 15.0.0.0< 15.0.5397.1001 |
affected |
| Microsoft | Microsoft Excel 2016 | 16.0.0.0< 16.0.5239.1001 |
affected |
| Microsoft | Microsoft Office 2019 | 19.0.0< https://aka.ms/OfficeSecurityReleases |
affected |
| Microsoft | Microsoft Office 2019 for Mac | 16.0.0< 16.55.21111400 |
affected |
| Microsoft | Microsoft Office LTSC 2021 | 16.0.1< https://aka.ms/OfficeSecurityReleases |
affected |
| Microsoft | Microsoft Office LTSC for Mac 2021 | 16.0.1< 16.55.21111400 |
affected |
| Microsoft | Microsoft Office Online Server | 16.0.1< 16.0.10380.20000 |
affected |
| Microsoft | Microsoft Office Web Apps Server 2013 Service Pack 1 | 15.0.1< 15.0.5397.1001 |
affected |
| Microsoft | Microsoft SharePoint Enterprise Server 2013 Service Pack 1 | 15.0.0< 15.0.5397.1001 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Microsoft | Microsoft 365 Apps for Enterprise | 16.0.1 ~ https://aka.ms/OfficeSecurityReleases | - |
|
| Microsoft | Microsoft Excel 2013 Service Pack 1 | 15.0.0.0 ~ 15.0.5397.1001 | - |
|
| Microsoft | Microsoft Excel 2016 | 16.0.0.0 ~ 16.0.5239.1001 | - |
|
| Microsoft | Microsoft Office 2019 | 19.0.0 ~ https://aka.ms/OfficeSecurityReleases | - |
|
| Microsoft | Microsoft Office 2019 for Mac | 16.0.0 ~ 16.55.21111400 | - |
|
| Microsoft | Microsoft Office LTSC 2021 | 16.0.1 ~ https://aka.ms/OfficeSecurityReleases | - |
|
| Microsoft | Microsoft Office LTSC for Mac 2021 | 16.0.1 ~ 16.55.21111400 | - |
|
| Microsoft | Microsoft Office Online Server | 16.0.1 ~ 16.0.10380.20000 | - |
|
| Microsoft | Microsoft Office Web Apps Server 2013 Service Pack 1 | 15.0.1 ~ 15.0.5397.1001 | - |
|
| Microsoft | Microsoft SharePoint Enterprise Server 2013 Service Pack 1 | 15.0.0 ~ 15.0.5397.1001 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-26443 | 9.0 CRITICAL | Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability |
| CVE-2021-38666 | 8.8 HIGH | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2021-42321 | 8.8 HIGH | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-42316 | 8.8 HIGH | Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability |
| CVE-2021-42275 | 8.8 HIGH | Microsoft COM for Windows Remote Code Execution Vulnerability |
| CVE-2021-42283 | 8.8 HIGH | NTFS Elevation of Privilege Vulnerability |
| CVE-2021-43209 | 7.8 HIGH | 3D Viewer Remote Code Execution Vulnerability |
| CVE-2021-43208 | 7.8 HIGH | 3D Viewer Remote Code Execution Vulnerability |
| CVE-2021-42296 | 7.8 HIGH | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2021-42298 | 7.8 HIGH | Microsoft Defender Remote Code Execution Vulnerability |
| CVE-2021-42292 | 7.8 HIGH | Microsoft Excel Security Feature Bypass Vulnerability |
| CVE-2021-42286 | 7.8 HIGH | Windows Core Shell SI Host Extension Framework for Composable Shell Elevation of Privilege |
| CVE-2021-42285 | 7.8 HIGH | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2021-42276 | 7.8 HIGH | Microsoft Windows Media Foundation Remote Code Execution Vulnerability |
| CVE-2021-41378 | 7.8 HIGH | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2021-41377 | 7.8 HIGH | Windows Fast FAT File System Driver Elevation of Privilege Vulnerability |
| CVE-2021-41370 | 7.8 HIGH | NTFS Elevation of Privilege Vulnerability |
| CVE-2021-41367 | 7.8 HIGH | NTFS Elevation of Privilege Vulnerability |
| CVE-2021-41366 | 7.8 HIGH | Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerabili |
| CVE-2021-36957 | 7.8 HIGH | Windows Desktop Bridge Elevation of Privilege Vulnerability |
Showing top 20 of 54 CVEs. View all on vendor page → →
No comments yet