peter bassill · operator
$ cve CVE-2021-38646 JSON

CVE-2021-38646 KEV

7.8
HIGH · CVSS 3.1 · EPSS 8% (pctl 95)

Patch first

On CISA KEV — known exploited in the wild, due 2022-04-18.

Description

Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability

Scoring

CVSS7.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS7.99% — more likely to be exploited than 95% of all CVEs
On CISA KEVyes — remediate by 2022-04-18
Public exploitnone known
Published2021-09-15
Last modified2026-08-10

CISA KEV

NameMicrosoft Office Access Connectivity Engine Remote Code Execution Vulnerability
Added2022-03-28
Due2022-04-18
Vendor / productMicrosoft / Office
Ransomware useknown

Affected (4)

VendorProduct
microsoft365 apps
microsoftoffice
microsoftoffice 2016
microsoftoffice 2019

References

→ the Explorer  ·  watch your stack  ·  NVD