7.8
CVE-2021-38646
- EPSS 7.99%
- Veröffentlicht 15.09.2021 12:15:15
- Zuletzt bearbeitet 10.08.2026 19:59:12
- CVE-Watchlists
- Unerledigt
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Office 2016 Version- SwEdition- HwPlatformx64
Microsoft ≫ Office 2016 Version- SwEdition- HwPlatformx86
Microsoft ≫ Office 2019 Version-
28.03.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
SchwachstelleMicrosoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution.
BeschreibungApply updates per vendor instructions.
Erforderliche Maßnahmen| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 7.99% | 0.942 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| Microsoft | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38646
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-38646
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-38646