CVE-2021-31177

Description

Microsoft Office Remote Code Execution Vulnerability

Risk Information

Base Score
7.7
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
EPSS Score
Exploitation Probability
10.83

Associated Vulnerability

VulnerabilityOS Platform
Microsoft Excel Information Disclosure Vulnerability for Microsoft Excel 2016 (KB5001918) 32-Bit EditionWindows
Microsoft Excel Information Disclosure Vulnerability for Microsoft Excel 2016 (KB5001918) 64-Bit EditionWindows
Microsoft Excel Information Disclosure Vulnerability for Microsoft Office Web Apps Server 2013 (KB5001928)Windows
Microsoft Excel Information Disclosure Vulnerability for Microsoft Excel 2013 (KB5001936) 64-Bit EditionWindows
Microsoft Excel Information Disclosure Vulnerability for Microsoft Excel 2013 (KB5001936) 32-Bit EditionWindows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Office 2019 for x86 1808 of version(10374.20040)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Office 2019 x64 1808 (Build:10374.20040)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Office 2019 for x64 1808 of version(10374.20040)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Channel for x64 2008 of version(13127.21624)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Channel for x86 2008 of version(13127.21624)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Semi Annual Channel for x64 2008 of version(13127.21624)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Semi Annual Channel for x86 2008 of version(13127.21624)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi-Annual Channel Version 2008 (Build 13127.21624) (Online Installer)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Channel for x86 2008 of version(13127.21624)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Channel for x64 2008 of version(13127.21624)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Semi Annual Channel for x86 2008 of version(13127.21624)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Semi Annual Channel for x64 2008 of version(13127.21624)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Targeted Channel for x64 2102 of version(13801.20638)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Targeted Channel for x86 2102 of version(13801.20638)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Targeted Channel Version 2102 (Build 13801.20638) (Online Installer)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Preview Channel for x86 2102 of version(13801.20638)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Preview Channel for x64 2102 of version(13801.20638)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Current Channel for x64 2104 of version(13929.20372)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Current Channel for x86 2104 of version(13929.20372)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Current Channel for x64 2104 of version(13929.20372)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Current Channel for x86 2104 of version(13929.20372)Windows
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Current Channel Version 2104 (Build 13929.20372) (Online Installer)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-31410Security Update for Microsoft Excel 2016 (KB5001918) 32-Bit Edition
PATCH-31411Security Update for Microsoft Excel 2016 (KB5001918) 64-Bit Edition
PATCH-31426Security Update for Microsoft Office Web Apps Server 2013 (KB5001928)
PATCH-31408Security Update for Microsoft Excel 2013 (KB5001936) 64-Bit Edition
PATCH-31409Security Update for Microsoft Excel 2013 (KB5001936) 32-Bit Edition
PATCH-31451Update for Office 2019 for x86 1808 of version(10374.20040)
PATCH-31452Office 2016 Deployment Tool for Office 2019 x64 1808 (Build:10374.20040)
PATCH-31453Update for Office 2019 for x64 1808 of version(10374.20040)
PATCH-31455Update for Microsoft 365 Apps for Enterprise Semi Annual Channel for x64 2008 of version(13127.21624)
PATCH-31457Update for Microsoft 365 Apps for Enterprise Semi Annual Channel for x86 2008 of version(13127.21624)
PATCH-31459Update for Microsoft 365 Apps for Business Semi Annual Channel for x64 2008 of version(13127.21624)
PATCH-31461Update for Microsoft 365 Apps for Business Semi Annual Channel for x86 2008 of version(13127.21624)
PATCH-31467Update for Microsoft 365 Apps for Enterprise Semi-Annual Channel Version 2008 (Build 13127.21624) (Online Installer)
PATCH-31503Update for Microsoft 365 Apps for Enterprise Semi Annual Channel for x86 2008 of version(13127.21624)
PATCH-31504Update for Microsoft 365 Apps for Enterprise Semi Annual Channel for x64 2008 of version(13127.21624)
PATCH-31505Update for Microsoft 365 Apps for Business Semi Annual Channel for x86 2008 of version(13127.21624)
PATCH-31506Update for Microsoft 365 Apps for Business Semi Annual Channel for x64 2008 of version(13127.21624)
PATCH-31463Update for Microsoft 365 Apps for Enterprise Semi Annual Targeted Channel for x64 2102 of version(13801.20638)
PATCH-31465Update for Microsoft 365 Apps for Enterprise Semi Annual Targeted Channel for x86 2102 of version(13801.20638)
PATCH-31468Update for Microsoft 365 Apps for Enterprise Targeted Channel Version 2102 (Build 13801.20638) (Online Installer)
PATCH-31509Update for Microsoft 365 Apps for Enterprise Semi Annual Preview Channel for x86 2102 of version(13801.20638)
PATCH-31511Update for Microsoft 365 Apps for Enterprise Semi Annual Preview Channel for x64 2102 of version(13801.20638)
PATCH-31443Update for Microsoft 365 Apps for Enterprise Current Channel for x64 2104 of version(13929.20372)
PATCH-31445Update for Microsoft 365 Apps for Enterprise Current Channel for x86 2104 of version(13929.20372)
PATCH-31447Update for Microsoft 365 Apps for Business Current Channel for x64 2104 of version(13929.20372)
PATCH-31449Update for Microsoft 365 Apps for Business Current Channel for x86 2104 of version(13929.20372)
PATCH-31466Update for Microsoft 365 Apps for Enterprise Current Channel Version 2104 (Build 13929.20372) (Online Installer)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234