CVE-2022-21840
Description
Microsoft Office Remote Code Execution Vulnerability
Risk Information
Base Score
8.7
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
EPSS Score
Exploitation Probability
7.197
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Microsoft SharePoint Server Remote Code Execution Vulnerability for Microsoft SharePoint Server 2019 Core (KB5002109) farm-deployment | Windows |
| Microsoft SharePoint Server Remote Code Execution Vulnerability for Microsoft SharePoint Enterprise Server 2016 (KB5002113) farm-deployment | Windows |
| Microsoft SharePoint Server Remote Code Execution Vulnerability for Microsoft SharePoint Foundation 2013 (KB5002127) | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Microsoft SharePoint Enterprise Server 2013 (KB5001995) | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Microsoft Office 2016 (KB5002052) 32-Bit Edition | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Microsoft Office 2016 (KB5002052) 64-Bit Edition | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Microsoft Office 2016 (KB5002060) 64-Bit Edition | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Microsoft Office 2016 (KB5002060) 32-Bit Edition | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Microsoft Office 2013 (KB5002064) 64-Bit Edition | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Microsoft Office 2013 (KB5002064) 32-Bit Edition | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Microsoft SharePoint Enterprise Server 2013 (KB5002102) | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Microsoft SharePoint Server 2019 Language Pack (KB5002108) farm-deployment | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Microsoft Excel 2016 (KB5002114) 64-Bit Edition | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Microsoft Excel 2016 (KB5002114) 32-Bit Edition | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Microsoft Office 2016 (KB5002115) 64-Bit Edition | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Microsoft Office 2016 (KB5002115) 32-Bit Edition | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Microsoft SharePoint Enterprise Server 2016 (KB5002118) farm-deployment | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Microsoft Office Web Apps Server 2013 (KB5002122) | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Microsoft Excel 2013 (KB5002128) 32-Bit Edition | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Microsoft Excel 2013 (KB5002128) 64-Bit Edition | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Microsoft SharePoint Foundation 2013 (KB5002129) | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Office 2019 for x86 1808 of version(10382.20034) | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Office 2019 for x64 1808 of version(10382.20034) | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Office 2019 for x64 1808 of volume version(10382.20034) | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Office 2019 for x86 1808 of volume version(10382.20034) | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Channel for x64 2108 of version(14326.20738) | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Channel for x86 2108 of version(14326.20738) | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Semi Annual Channel for x64 2108 of version(14326.20738) | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Semi Annual Channel for x86 2108 of version(14326.20738) | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Targeted Channel for x64 2108 of version(14326.20738) | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Targeted Channel for x86 2108 of version(14326.20738) | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi-Annual Channel Version 2108 (Build 14326.20738) (Online Installer) | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Targeted Channel Version 2108 (Build 14326.20738) (Online Installer) | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Semi Annual Channel for x64 2108 of version(14326.20738) | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Semi Annual Channel for x86 2108 of version(14326.20738) | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Channel for x64 2108 of version(14326.20738) | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Channel for x86 2108 of version(14326.20738) | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Preview Channel for x64 2108 of version(14326.20738) | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Preview Channel for x86 2108 of version(14326.20738) | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Office 2021 for x64 2108 of volume version(14332.20216) | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Office 2021 for x86 2108 of volume version(14332.20216) | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Microsoft 365 Apps for Monthly Enterprise Channel for x64 2111 of version(14701.20290) | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Microsoft 365 Apps for Monthly Enterprise Channel for x86 version 2111 (14701.20290) | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Current Channel for x64 2112 of version(14729.20248) | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Current Channel for x86 2112 of version(14729.20248) | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Current Channel for x64 2112 of version(14729.20248) | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Current Channel for x86 2112 of version(14729.20248) | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Current Channel Version 2112 (Build 14729.20248) (Online Installer) | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Current Channel for x64 2112 of version(14729.20248) | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Current Channel for x86 2112 of version(14729.20248) | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Current Channel for x64 2112 of version(14729.20248) | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Current Channel for x86 2112 of version(14729.20248) | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Office 2019 for x64 2112 Retail Version (14729.20248) | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Office 2019 for x86 2112 Retail Version (14729.20248) | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Office 2021 for x64 2112 of volume version(14729.20248) | Windows |
| Microsoft Office Remote Code Execution Vulnerability for Office 2021 for x86 2112 of Retail Version(14729.20248) | Windows |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-32885 | Security Update for Microsoft SharePoint Enterprise Server 2016 (KB5002113) farm-deployment |
| PATCH-32891 | Security Update for Microsoft SharePoint Foundation 2013 (KB5002127) |
| PATCH-32915 | Security Update for Microsoft SharePoint Enterprise Server 2013 (KB5001995) |
| PATCH-32908 | Security Update for Microsoft Office 2016 (KB5002052) 32-Bit Edition |
| PATCH-32909 | Security Update for Microsoft Office 2016 (KB5002052) 64-Bit Edition |
| PATCH-32904 | Security Update for Microsoft Office 2016 (KB5002060) 64-Bit Edition |
| PATCH-32905 | Security Update for Microsoft Office 2016 (KB5002060) 32-Bit Edition |
| PATCH-32896 | Security Update for Microsoft Office 2013 (KB5002064) 64-Bit Edition |
| PATCH-32897 | Security Update for Microsoft Office 2013 (KB5002064) 32-Bit Edition |
| PATCH-32916 | Security Update for Microsoft SharePoint Enterprise Server 2013 (KB5002102) |
| PATCH-32914 | Security Update for Microsoft SharePoint Server 2019 Language Pack (KB5002108) farm-deployment |
| PATCH-32910 | Security Update for Microsoft Excel 2016 (KB5002114) 64-Bit Edition |
| PATCH-32911 | Security Update for Microsoft Excel 2016 (KB5002114) 32-Bit Edition |
| PATCH-32906 | Security Update for Microsoft Office 2016 (KB5002115) 64-Bit Edition |
| PATCH-32907 | Security Update for Microsoft Office 2016 (KB5002115) 32-Bit Edition |
| PATCH-32886 | Security Update for Microsoft SharePoint Enterprise Server 2016 (KB5002118) farm-deployment |
| PATCH-32895 | Security Update for Microsoft Office Web Apps Server 2013 (KB5002122) |
| PATCH-32902 | Security Update for Microsoft Excel 2013 (KB5002128) 32-Bit Edition |
| PATCH-32903 | Security Update for Microsoft Excel 2013 (KB5002128) 64-Bit Edition |
| PATCH-32894 | Security Update for Microsoft SharePoint Foundation 2013 (KB5002129) |
| PATCH-32928 | Update for Office 2019 for x86 1808 of version(10382.20034) |
| PATCH-32930 | Update for Office 2019 for x64 1808 of version(10382.20034) |
| PATCH-32971 | Update for Office 2019 for x64 1808 of volume version(10382.20034) |
| PATCH-32973 | Update for Office 2019 for x86 1808 of volume version(10382.20034) |
| PATCH-32932 | Update for Microsoft 365 Apps for Enterprise Semi Annual Channel for x64 2108 of version(14326.20738) |
| PATCH-32934 | Update for Microsoft 365 Apps for Enterprise Semi Annual Channel for x86 2108 of version(14326.20738) |
| PATCH-32936 | Update for Microsoft 365 Apps for Business Semi Annual Channel for x64 2108 of version(14326.20738) |
| PATCH-32938 | Update for Microsoft 365 Apps for Business Semi Annual Channel for x86 2108 of version(14326.20738) |
| PATCH-32940 | Update for Microsoft 365 Apps for Enterprise Semi Annual Targeted Channel for x64 2108 of version(14326.20738) |
| PATCH-32942 | Update for Microsoft 365 Apps for Enterprise Semi Annual Targeted Channel for x86 2108 of version(14326.20738) |
| PATCH-32943 | Update for Microsoft 365 Apps for Enterprise Semi-Annual Channel Version 2108 (Build 14326.20738) (Online Installer) |
| PATCH-32944 | Update for Microsoft 365 Apps for Enterprise Targeted Channel Version 2108 (Build 14326.20738) (Online Installer) |
| PATCH-32959 | Update for Microsoft 365 Apps for Business Semi Annual Channel for x64 2108 of version(14326.20738) |
| PATCH-32961 | Update for Microsoft 365 Apps for Business Semi Annual Channel for x86 2108 of version(14326.20738) |
| PATCH-32963 | Update for Microsoft 365 Apps for Enterprise Semi Annual Channel for x64 2108 of version(14326.20738) |
| PATCH-32965 | Update for Microsoft 365 Apps for Enterprise Semi Annual Channel for x86 2108 of version(14326.20738) |
| PATCH-32967 | Update for Microsoft 365 Apps for Enterprise Semi Annual Preview Channel for x64 2108 of version(14326.20738) |
| PATCH-32969 | Update for Microsoft 365 Apps for Enterprise Semi Annual Preview Channel for x86 2108 of version(14326.20738) |
| PATCH-32979 | Update for Office 2021 for x64 2108 of volume version(14332.20216) |
| PATCH-32981 | Update for Office 2021 for x86 2108 of volume version(14332.20216) |
| PATCH-32955 | Update for Microsoft 365 Apps for Monthly Enterprise Channel for x64 2111 of version(14701.20290) |
| PATCH-32957 | Update for Microsoft 365 Apps for Monthly Enterprise Channel for x86 version 2111 (14701.20290) |
| PATCH-32920 | Update for Microsoft 365 Apps for Enterprise Current Channel for x64 2112 of version(14729.20248) |
| PATCH-32922 | Update for Microsoft 365 Apps for Enterprise Current Channel for x86 2112 of version(14729.20248) |
| PATCH-32924 | Update for Microsoft 365 Apps for Business Current Channel for x64 2112 of version(14729.20248) |
| PATCH-32926 | Update for Microsoft 365 Apps for Business Current Channel for x86 2112 of version(14729.20248) |
| PATCH-32945 | Update for Microsoft 365 Apps for Enterprise Current Channel Version 2112 (Build 14729.20248) (Online Installer) |
| PATCH-32947 | Update for Microsoft 365 Apps for Business Current Channel for x64 2112 of version(14729.20248) |
| PATCH-32949 | Update for Microsoft 365 Apps for Business Current Channel for x86 2112 of version(14729.20248) |
| PATCH-32951 | Update for Microsoft 365 Apps for Enterprise Current Channel for x64 2112 of version(14729.20248) |
| PATCH-32953 | Update for Microsoft 365 Apps for Enterprise Current Channel for x86 2112 of version(14729.20248) |
| PATCH-32975 | Update for Office 2019 for x64 2112 Retail Version (14729.20248) |
| PATCH-32977 | Update for Office 2019 for x86 2112 Retail Version (14729.20248) |
| PATCH-32983 | Update for Office 2021 for x64 2112 of volume version(14729.20248) |
| PATCH-32985 | Update for Office 2021 for x86 2112 of Retail Version(14729.20248) |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234