7.8
CVE-2021-38646
- EPSS 64.94%
- Published 15.09.2021 12:15:15
- Last modified 07.03.2025 21:54:07
- Source secure@microsoft.com
- Teams watchlist Login
- Open Login
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
Data is provided by the National Vulnerability Database (NVD)
28.03.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
VulnerabilityMicrosoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution.
DescriptionApply updates per vendor instructions.
Required actionsType | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 64.94% | 0.984 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
secure@microsoft.com | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|