Lucene search

K
mscveMicrosoftMS:CVE-2021-34469
HistoryJul 13, 2021 - 7:00 a.m.

Microsoft Office Security Feature Bypass Vulnerability

2021-07-1307:00:00
Microsoft
msrc.microsoft.com
21
office security feature bypass

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

CVSS3

8.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N

AI Score

8.1

Confidence

High

EPSS

0.004

Percentile

72.9%

Affected configurations

Vulners
Node
microsoftoffice_2013_rtRange<15.0.5363.1000
OR
microsoftoffice_2013_rtRange<15.0.5363.1000
OR
microsoftoffice_2013_rtRange<15.0.5363.1000
OR
microsoftmicrosoft_office_2016_\(64-bit_edition\)Range<16.0.5188.1000
OR
microsoftmicrosoft_office_2016_\(32-bit_edition\)Range<16.0.5188.1000
OR
microsoft365_appsRange<https://aka.ms/OfficeSecurityReleasesenterprise
OR
microsoft365_appsRange<https://aka.ms/OfficeSecurityReleasesenterprise
OR
microsoftmicrosoft_office_2019_for_64-bit_editionsRange<https://aka.ms/OfficeSecurityReleases
OR
microsoftmicrosoft_office_2019_for_32-bit_editionsRange<https://aka.ms/OfficeSecurityReleases
VendorProductVersionCPE
microsoftoffice_2013_rt*cpe:2.3:a:microsoft:office_2013_rt:*:*:*:*:*:*:*:*
microsoftmicrosoft_office_2016_\(64-bit_edition\)*cpe:2.3:a:microsoft:microsoft_office_2016_\(64-bit_edition\):*:*:*:*:*:*:*:*
microsoftmicrosoft_office_2016_\(32-bit_edition\)*cpe:2.3:a:microsoft:microsoft_office_2016_\(32-bit_edition\):*:*:*:*:*:*:*:*
microsoft365_apps*cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:*
microsoftmicrosoft_office_2019_for_64-bit_editions*cpe:2.3:a:microsoft:microsoft_office_2019_for_64-bit_editions:*:*:*:*:*:*:*:*
microsoftmicrosoft_office_2019_for_32-bit_editions*cpe:2.3:a:microsoft:microsoft_office_2019_for_32-bit_editions:*:*:*:*:*:*:*:*

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

CVSS3

8.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N

AI Score

8.1

Confidence

High

EPSS

0.004

Percentile

72.9%