PT-2021-2035 · Microsoft · Office Excel+4

Published

2021-02-09

·

Updated

2023-12-29

·

CVE-2021-24070

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Microsoft Excel (affected versions not specified) Microsoft Office (affected versions not specified) Microsoft 365 Apps for Enterprise (affected versions not specified) Microsoft Office Web Apps Server (affected versions not specified) Microsoft Office Online Server (affected versions not specified)
Description: The issue is related to insufficient input validation in Microsoft products, which can allow a remote attacker to execute arbitrary code. This can be achieved through the exploitation of a use-after-free vulnerability in the parsing of XLS files in Microsoft Excel.
Recommendations: For Microsoft Excel, consider restricting the opening of XLS files from untrusted sources until a fix is available. For Microsoft Office, apply configuration changes to minimize the risk of exploitation, such as disabling the execution of macros from untrusted sources. For Microsoft 365 Apps for Enterprise, Office Web Apps Server, and Office Online Server, restrict access to vulnerable components to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-00879
CVE-2021-24070
ZDI-21-181

Affected Products

365 Apps For Enterprise
Office Excel
Office
Office Online Server
Office Web Apps Server