CVE-2021-31180
Description
Microsoft Office Graphics Remote Code Execution Vulnerability
Risk Information
Base Score
7.7
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
EPSS Score
Exploitation Probability
10.289
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Microsoft Office Graphics Remote Code Execution Vulnerability for Microsoft Office 2013 (KB4464542) 64-Bit Edition | Windows |
| Microsoft Office Graphics Remote Code Execution Vulnerability for Microsoft Office 2013 (KB4464542) 32-Bit Edition | Windows |
| Microsoft Office Graphics Remote Code Execution Vulnerability for Microsoft Word 2016 (KB5001919) 64-Bit Edition | Windows |
| Microsoft Office Graphics Remote Code Execution Vulnerability for Microsoft Word 2016 (KB5001919) 32-Bit Edition | Windows |
| Microsoft Office Graphics Remote Code Execution Vulnerability for Microsoft Word 2013 (KB5001931) 32-Bit Edition | Windows |
| Microsoft Office Graphics Remote Code Execution Vulnerability for Microsoft Word 2013 (KB5001931) 64-Bit Edition | Windows |
| Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Office 2019 for x86 1808 of version(10374.20040) | Windows |
| Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Office 2019 x64 1808 (Build:10374.20040) | Windows |
| Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Office 2019 for x64 1808 of version(10374.20040) | Windows |
| Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Channel for x64 2008 of version(13127.21624) | Windows |
| Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Channel for x86 2008 of version(13127.21624) | Windows |
| Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Semi Annual Channel for x64 2008 of version(13127.21624) | Windows |
| Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Semi Annual Channel for x86 2008 of version(13127.21624) | Windows |
| Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi-Annual Channel Version 2008 (Build 13127.21624) (Online Installer) | Windows |
| Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Channel for x86 2008 of version(13127.21624) | Windows |
| Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Channel for x64 2008 of version(13127.21624) | Windows |
| Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Semi Annual Channel for x86 2008 of version(13127.21624) | Windows |
| Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Semi Annual Channel for x64 2008 of version(13127.21624) | Windows |
| Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Targeted Channel for x64 2102 of version(13801.20638) | Windows |
| Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Targeted Channel for x86 2102 of version(13801.20638) | Windows |
| Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Targeted Channel Version 2102 (Build 13801.20638) (Online Installer) | Windows |
| Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Preview Channel for x86 2102 of version(13801.20638) | Windows |
| Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Preview Channel for x64 2102 of version(13801.20638) | Windows |
| Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Current Channel for x64 2104 of version(13929.20372) | Windows |
| Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Current Channel for x86 2104 of version(13929.20372) | Windows |
| Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Current Channel for x64 2104 of version(13929.20372) | Windows |
| Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Current Channel for x86 2104 of version(13929.20372) | Windows |
| Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Current Channel Version 2104 (Build 13929.20372) (Online Installer) | Windows |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-31412 | Security Update for Microsoft Office 2013 (KB4464542) 64-Bit Edition |
| PATCH-31413 | Security Update for Microsoft Office 2013 (KB4464542) 32-Bit Edition |
| PATCH-31430 | Security Update for Microsoft Word 2016 (KB5001919) 64-Bit Edition |
| PATCH-31431 | Security Update for Microsoft Word 2016 (KB5001919) 32-Bit Edition |
| PATCH-31428 | Security Update for Microsoft Word 2013 (KB5001931) 32-Bit Edition |
| PATCH-31429 | Security Update for Microsoft Word 2013 (KB5001931) 64-Bit Edition |
| PATCH-31451 | Update for Office 2019 for x86 1808 of version(10374.20040) |
| PATCH-31452 | Office 2016 Deployment Tool for Office 2019 x64 1808 (Build:10374.20040) |
| PATCH-31453 | Update for Office 2019 for x64 1808 of version(10374.20040) |
| PATCH-31455 | Update for Microsoft 365 Apps for Enterprise Semi Annual Channel for x64 2008 of version(13127.21624) |
| PATCH-31457 | Update for Microsoft 365 Apps for Enterprise Semi Annual Channel for x86 2008 of version(13127.21624) |
| PATCH-31459 | Update for Microsoft 365 Apps for Business Semi Annual Channel for x64 2008 of version(13127.21624) |
| PATCH-31461 | Update for Microsoft 365 Apps for Business Semi Annual Channel for x86 2008 of version(13127.21624) |
| PATCH-31467 | Update for Microsoft 365 Apps for Enterprise Semi-Annual Channel Version 2008 (Build 13127.21624) (Online Installer) |
| PATCH-31503 | Update for Microsoft 365 Apps for Enterprise Semi Annual Channel for x86 2008 of version(13127.21624) |
| PATCH-31504 | Update for Microsoft 365 Apps for Enterprise Semi Annual Channel for x64 2008 of version(13127.21624) |
| PATCH-31505 | Update for Microsoft 365 Apps for Business Semi Annual Channel for x86 2008 of version(13127.21624) |
| PATCH-31506 | Update for Microsoft 365 Apps for Business Semi Annual Channel for x64 2008 of version(13127.21624) |
| PATCH-31463 | Update for Microsoft 365 Apps for Enterprise Semi Annual Targeted Channel for x64 2102 of version(13801.20638) |
| PATCH-31465 | Update for Microsoft 365 Apps for Enterprise Semi Annual Targeted Channel for x86 2102 of version(13801.20638) |
| PATCH-31468 | Update for Microsoft 365 Apps for Enterprise Targeted Channel Version 2102 (Build 13801.20638) (Online Installer) |
| PATCH-31509 | Update for Microsoft 365 Apps for Enterprise Semi Annual Preview Channel for x86 2102 of version(13801.20638) |
| PATCH-31511 | Update for Microsoft 365 Apps for Enterprise Semi Annual Preview Channel for x64 2102 of version(13801.20638) |
| PATCH-31443 | Update for Microsoft 365 Apps for Enterprise Current Channel for x64 2104 of version(13929.20372) |
| PATCH-31445 | Update for Microsoft 365 Apps for Enterprise Current Channel for x86 2104 of version(13929.20372) |
| PATCH-31447 | Update for Microsoft 365 Apps for Business Current Channel for x64 2104 of version(13929.20372) |
| PATCH-31449 | Update for Microsoft 365 Apps for Business Current Channel for x86 2104 of version(13929.20372) |
| PATCH-31466 | Update for Microsoft 365 Apps for Enterprise Current Channel Version 2104 (Build 13929.20372) (Online Installer) |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234