PT-2021-2624 · Microsoft · Office Web Apps Server+1

Published

2021-04-13

·

Updated

2023-12-29

·

CVE-2021-28451

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Microsoft Excel (affected versions not specified)
Description: The issue is related to errors in code generation management in Microsoft Office packages, including Microsoft Excel and Microsoft Office Web Apps Server. Exploitation of this issue may allow an attacker to execute arbitrary code using a specially crafted file.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2021-02114
CVE-2021-28451

Affected Products

Office Excel
Office Web Apps Server