CVE-2021-28455

Description

Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability

Risk Information

Base Score
8.7
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
EPSS Score
Exploitation Probability
8.688

Associated Vulnerability

VulnerabilityOS Platform
Windows Wireless Networking Information Disclosure Vulnerability for Windows 10 Version 1909 for x64-based Systems (KB5003169)Windows
Windows Wireless Networking Information Disclosure Vulnerability for Windows Server, version 1909 for x64-based Systems (KB5003169)Windows
Windows Wireless Networking Information Disclosure Vulnerability for Windows 10 Version 1909 for x86-based Systems (KB5003169)Windows
Windows Wireless Networking Information Disclosure Vulnerability for Windows 10 Version 1809 for x64-based Systems (KB5003171)Windows
Windows Wireless Networking Information Disclosure Vulnerability for Windows Server 2019 for x64-based Systems (KB5003171)Windows
Windows Wireless Networking Information Disclosure Vulnerability for Windows 10 Version 1809 for x86-based Systems (KB5003171)Windows
Windows Wireless Networking Information Disclosure Vulnerability for Windows 10 Version 1507 for x64-based Systems (KB5003172)Windows
Windows Wireless Networking Information Disclosure Vulnerability for Windows 10 Version 1507 for x86-based Systems (KB5003172)Windows
Windows Wireless Networking Information Disclosure Vulnerability for Windows Server, version 2004 for x64-based Systems (KB5003173)Windows
Windows Wireless Networking Information Disclosure Vulnerability for Windows 10 Version 2004 for x64-based Systems (KB5003173)Windows
Windows Wireless Networking Information Disclosure Vulnerability for Windows 10 Version 2004 for x86-based Systems (KB5003173)Windows
Windows Wireless Networking Information Disclosure Vulnerability for Windows 10 Version 20H2 for x64-based Systems (KB5003173)Windows
Windows Wireless Networking Information Disclosure Vulnerability for Windows 10 Version 20H2 for x86-based Systems (KB5003173)Windows
Windows Wireless Networking Information Disclosure Vulnerability for Windows 10 Version 1803 for x64-based Systems (KB5003174)Windows
Windows Wireless Networking Information Disclosure Vulnerability for Windows 10 Version 1803 for x86-based Systems (KB5003174)Windows
Windows Wireless Networking Information Disclosure Vulnerability for Windows Server 2016 for x64-based Systems (KB5003197)Windows
Windows Wireless Networking Information Disclosure Vulnerability for Windows 10 Version 1607 for x64-based Systems (KB5003197)Windows
Windows Wireless Networking Information Disclosure Vulnerability for Windows 10 Version 1607 for x86-based Systems (KB5003197)Windows
Windows Wireless Networking Information Disclosure Vulnerability for Windows Server 2012 for x64-based Systems (KB5003203)Windows
Windows Wireless Networking Information Disclosure Vulnerability for Windows Server 2012 for x64-based Systems (KB5003208)Windows
Windows Wireless Networking Information Disclosure Vulnerability for Windows Server 2012 R2 for x64-based Systems (KB5003209)Windows
Windows Wireless Networking Information Disclosure Vulnerability for Windows 8.1 for x64-based Systems (KB5003209)Windows
Windows Wireless Networking Information Disclosure Vulnerability for Windows 8.1 for x86-based Systems (KB5003209)Windows
Windows Wireless Networking Information Disclosure Vulnerability for Windows Server 2008 for x64-based Systems (KB5003210) (ESU)Windows
Windows Wireless Networking Information Disclosure Vulnerability for Windows Server 2008 for x86-based Systems (KB5003210) (ESU)Windows
Windows Wireless Networking Information Disclosure Vulnerability for Windows Server 2012 R2 for x64-based Systems (KB5003220)Windows
Windows Wireless Networking Information Disclosure Vulnerability for Windows 8.1 for x64-based Systems (KB5003220)Windows
Windows Wireless Networking Information Disclosure Vulnerability for Windows 8.1 for x86-based Systems (KB5003220)Windows
Windows Wireless Networking Information Disclosure Vulnerability for Windows Server 2008 for x64-based Systems (KB5003225) (ESU)Windows
Windows Wireless Networking Information Disclosure Vulnerability for Windows Server 2008 for x86-based Systems (KB5003225) (ESU)Windows
Windows Wireless Networking Information Disclosure Vulnerability for Windows Server 2008 R2 for x64-based Systems (KB5003228) (ESU)Windows
Windows Wireless Networking Information Disclosure Vulnerability for Windows 7 for x64-based Systems (KB5003228) (ESU)Windows
Windows Wireless Networking Information Disclosure Vulnerability for Windows 7 for x86-based Systems (KB5003228) (ESU)Windows
Windows Wireless Networking Information Disclosure Vulnerability for Windows Server 2008 R2 for x64-based Systems (KB5003233) (ESU)Windows
Windows Wireless Networking Information Disclosure Vulnerability for Windows 7 for x64-based Systems (KB5003233) (ESU)Windows
Windows Wireless Networking Information Disclosure Vulnerability for Windows 7 for x86-based Systems (KB5003233) (ESU)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft Office 2016 (KB4493197) 32-Bit EditionWindows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft Office 2016 (KB4493197) 64-Bit EditionWindows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft Office 2013 (KB4493206) 64-Bit EditionWindows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft Office 2013 (KB4493206) 32-Bit EditionWindows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Office 2019 for x86 1808 of version(10374.20040)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Office 2019 x64 1808 (Build:10374.20040)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Office 2019 for x64 1808 of version(10374.20040)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Office 2019 for x86 1808 of version(10375.20036)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Office 2019 x64 1808 (Build:10375.20036)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Office 2019 for x64 1808 of version(10375.20036)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Channel for x64 2008 of version(13127.21624)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Channel for x86 2008 of version(13127.21624)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Semi Annual Channel for x64 2008 of version(13127.21624)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Semi Annual Channel for x86 2008 of version(13127.21624)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi-Annual Channel Version 2008 (Build 13127.21624) (Online Installer)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Channel for x86 2008 of version(13127.21624)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Channel for x64 2008 of version(13127.21624)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Semi Annual Channel for x86 2008 of version(13127.21624)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Semi Annual Channel for x64 2008 of version(13127.21624)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Channel for x64 2008 of version(13127.21668)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Channel for x86 2008 of version(13127.21668)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Semi Annual Channel for x64 2008 of version(13127.21668)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Semi Annual Channel for x86 2008 of version(13127.21668)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi-Annual Channel Version 2008 (Build 13127.21668) (Online Installer)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Targeted Channel for x64 2102 of version(13801.20638)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Targeted Channel for x86 2102 of version(13801.20638)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Targeted Channel Version 2102 (Build 13801.20638) (Online Installer)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Preview Channel for x86 2102 of version(13801.20638)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Preview Channel for x64 2102 of version(13801.20638)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Targeted Channel for x64 2102 of version(13801.20738)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Targeted Channel for x86 2102 of version(13801.20738)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Targeted Channel Version 2102 (Build 13801.20738) (Online Installer)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Current Channel for x64 2104 of version(13929.20372)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Current Channel for x86 2104 of version(13929.20372)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Current Channel for x64 2104 of version(13929.20372)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Current Channel for x86 2104 of version(13929.20372)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Current Channel Version 2104 (Build 13929.20372) (Online Installer)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Current Channel for x64 2105 of version(14026.20270)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Current Channel for x86 2105 of version(14026.20270)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Current Channel for x64 2105 of version(14026.20270)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Current Channel for x86 2105 of version(14026.20270)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Current Channel Version 2105 (Build 14026.20270) (Online Installer)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-313762021-05 Cumulative Update for Windows 10 Version 1909 for x64-based Systems (KB5003169)
PATCH-313772021-05 Cumulative Update for Windows Server, version 1909 for x64-based Systems (KB5003169)
PATCH-313782021-05 Cumulative Update for Windows 10 Version 1909 for x86-based Systems (KB5003169)
PATCH-313812021-05 Cumulative Update for Windows 10 Version 1809 for x64-based Systems (KB5003171)
PATCH-313822021-05 Cumulative Update for Windows Server 2019 for x64-based Systems (KB5003171)
PATCH-314052021-05 Cumulative Update for Windows 10 Version 1809 for x86-based Systems (KB5003171)
PATCH-313742021-05 Cumulative Update for Windows 10 Version 1507 for x64-based Systems (KB5003172)
PATCH-313752021-05 Cumulative Update for Windows 10 Version 1507 for x86-based Systems (KB5003172)
PATCH-313352021-05 Cumulative Update for Windows Server, version 2004 for x64-based Systems (KB5003173)
PATCH-313362021-05 Cumulative Update for Windows 10 Version 2004 for x64-based Systems (KB5003173)
PATCH-313372021-05 Cumulative Update for Windows 10 Version 2004 for x86-based Systems (KB5003173)
PATCH-313382021-05 Cumulative Update for Windows 10 Version 20H2 for x64-based Systems (KB5003173)
PATCH-313392021-05 Cumulative Update for Windows 10 Version 20H2 for x86-based Systems (KB5003173)
PATCH-314062021-05 Cumulative Update for Windows 10 Version 1803 for x64-based Systems (KB5003174)
PATCH-314072021-05 Cumulative Update for Windows 10 Version 1803 for x86-based Systems (KB5003174)
PATCH-313442021-05 Cumulative Update for Windows Server 2016 for x64-based Systems (KB5003197)
PATCH-313452021-05 Cumulative Update for Windows 10 Version 1607 for x64-based Systems (KB5003197)
PATCH-313552021-05 Cumulative Update for Windows 10 Version 1607 for x86-based Systems (KB5003197)
PATCH-313302021-05 Security Only Quality Update for Windows Server 2012 for x64-based Systems (KB5003203)
PATCH-313342021-05 Security Monthly Quality Rollup for Windows Server 2012 for x64-based Systems (KB5003208)
PATCH-313312021-05 Security Monthly Quality Rollup for Windows Server 2012 R2 for x64-based Systems (KB5003209)
PATCH-313322021-05 Security Monthly Quality Rollup for Windows 8.1 for x64-based Systems (KB5003209)
PATCH-313332021-05 Security Monthly Quality Rollup for Windows 8.1 for x86-based Systems (KB5003209)
PATCH-313592021-05 Security Monthly Quality Rollup for Windows Server 2008 for x64-based Systems (KB5003210) (ESU)
PATCH-313602021-05 Security Monthly Quality Rollup for Windows Server 2008 for x86-based Systems (KB5003210) (ESU)
PATCH-313272021-05 Security Only Quality Update for Windows Server 2012 R2 for x64-based Systems (KB5003220)
PATCH-313282021-05 Security Only Quality Update for Windows 8.1 for x64-based Systems (KB5003220)
PATCH-313292021-05 Security Only Quality Update for Windows 8.1 for x86-based Systems (KB5003220)
PATCH-313642021-05 Security Only Quality Update for Windows Server 2008 for x64-based Systems (KB5003225) (ESU)
PATCH-313652021-05 Security Only Quality Update for Windows Server 2008 for x86-based Systems (KB5003225) (ESU)
PATCH-313612021-05 Security Only Quality Update for Windows Server 2008 R2 for x64-based Systems (KB5003228) (ESU)
PATCH-313622021-05 Security Only Quality Update for Windows 7 for x64-based Systems (KB5003228) (ESU)
PATCH-313632021-05 Security Only Quality Update for Windows 7 for x86-based Systems (KB5003228) (ESU)
PATCH-313562021-05 Security Monthly Quality Rollup for Windows Server 2008 R2 for x64-based Systems (KB5003233) (ESU)
PATCH-313572021-05 Security Monthly Quality Rollup for Windows 7 for x64-based Systems (KB5003233) (ESU)
PATCH-313582021-05 Security Monthly Quality Rollup for Windows 7 for x86-based Systems (KB5003233) (ESU)
PATCH-31420Security Update for Microsoft Office 2016 (KB4493197) 32-Bit Edition
PATCH-31421Security Update for Microsoft Office 2016 (KB4493197) 64-Bit Edition
PATCH-31414Security Update for Microsoft Office 2013 (KB4493206) 64-Bit Edition
PATCH-31415Security Update for Microsoft Office 2013 (KB4493206) 32-Bit Edition
PATCH-31451Update for Office 2019 for x86 1808 of version(10374.20040)
PATCH-31452Office 2016 Deployment Tool for Office 2019 x64 1808 (Build:10374.20040)
PATCH-31453Update for Office 2019 for x64 1808 of version(10374.20040)
PATCH-31621Update for Office 2019 for x86 1808 Volume License Version(10375.20036)
PATCH-31622Office 2016 Deployment Tool for Office 2019 x64 1808 (Build:10375.20036)
PATCH-31623Update for Office 2019 for x64 1808 Volume License Version(10375.20036)
PATCH-31455Update for Microsoft 365 Apps for Enterprise Semi Annual Channel for x64 2008 of version(13127.21624)
PATCH-31457Update for Microsoft 365 Apps for Enterprise Semi Annual Channel for x86 2008 of version(13127.21624)
PATCH-31459Update for Microsoft 365 Apps for Business Semi Annual Channel for x64 2008 of version(13127.21624)
PATCH-31461Update for Microsoft 365 Apps for Business Semi Annual Channel for x86 2008 of version(13127.21624)
PATCH-31467Update for Microsoft 365 Apps for Enterprise Semi-Annual Channel Version 2008 (Build 13127.21624) (Online Installer)
PATCH-31503Update for Microsoft 365 Apps for Enterprise Semi Annual Channel for x86 2008 of version(13127.21624)
PATCH-31504Update for Microsoft 365 Apps for Enterprise Semi Annual Channel for x64 2008 of version(13127.21624)
PATCH-31505Update for Microsoft 365 Apps for Business Semi Annual Channel for x86 2008 of version(13127.21624)
PATCH-31506Update for Microsoft 365 Apps for Business Semi Annual Channel for x64 2008 of version(13127.21624)
PATCH-31625Update for Microsoft 365 Apps for Enterprise Semi Annual Channel for x64 2008 of version(13127.21668)
PATCH-31627Update for Microsoft 365 Apps for Enterprise Semi Annual Channel for x86 2008 of version(13127.21668)
PATCH-31629Update for Microsoft 365 Apps for Business Semi Annual Channel for x64 2008 of version(13127.21668)
PATCH-31631Update for Microsoft 365 Apps for Business Semi Annual Channel for x86 2008 of version(13127.21668)
PATCH-31636Update for Microsoft 365 Apps for Enterprise Semi-Annual Channel Version 2008 (Build 13127.21668) (Online Installer)
PATCH-31463Update for Microsoft 365 Apps for Enterprise Semi Annual Targeted Channel for x64 2102 of version(13801.20638)
PATCH-31465Update for Microsoft 365 Apps for Enterprise Semi Annual Targeted Channel for x86 2102 of version(13801.20638)
PATCH-31468Update for Microsoft 365 Apps for Enterprise Targeted Channel Version 2102 (Build 13801.20638) (Online Installer)
PATCH-31509Update for Microsoft 365 Apps for Enterprise Semi Annual Preview Channel for x86 2102 of version(13801.20638)
PATCH-31511Update for Microsoft 365 Apps for Enterprise Semi Annual Preview Channel for x64 2102 of version(13801.20638)
PATCH-31633Update for Microsoft 365 Apps for Enterprise Semi Annual Targeted Channel for x64 2102 of version(13801.20738)
PATCH-31635Update for Microsoft 365 Apps for Enterprise Semi Annual Targeted Channel for x86 2102 of version(13801.20738)
PATCH-31637Update for Microsoft 365 Apps for Enterprise Targeted Channel Version 2102 (Build 13801.20738) (Online Installer)
PATCH-31443Update for Microsoft 365 Apps for Enterprise Current Channel for x64 2104 of version(13929.20372)
PATCH-31445Update for Microsoft 365 Apps for Enterprise Current Channel for x86 2104 of version(13929.20372)
PATCH-31447Update for Microsoft 365 Apps for Business Current Channel for x64 2104 of version(13929.20372)
PATCH-31449Update for Microsoft 365 Apps for Business Current Channel for x86 2104 of version(13929.20372)
PATCH-31466Update for Microsoft 365 Apps for Enterprise Current Channel Version 2104 (Build 13929.20372) (Online Installer)
PATCH-31613Update for Microsoft 365 Apps for Enterprise Current Channel for x64 2105 of version(14026.20270)
PATCH-31615Update for Microsoft 365 Apps for Enterprise Current Channel for x86 2105 of version(14026.20270)
PATCH-31617Update for Microsoft 365 Apps for Business Current Channel for x64 2105 of version(14026.20270)
PATCH-31619Update for Microsoft 365 Apps for Business Current Channel for x86 2105 of version(14026.20270)
PATCH-31638Update for Microsoft 365 Apps for Enterprise Current Channel Version 2105 (Build 14026.20270) (Online Installer)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234