CVE-2021-27059
Microsoft Office Remote Code Execution Vulnerability
Description
CVE-2021-27059 is a high-severity remote code execution vulnerability affecting Microsoft Office 2010, 2013, and 2016. The vulnerability allows an attacker to execute arbitrary code remotely by exploiting an unspecified flaw in Microsoft Office. CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild. With a CVSS 3.1 score of 7.6 and an EPSS score of 2.05% (83.6th percentile), this vulnerability represents a meaningful risk, particularly given the high attack complexity is offset by its confirmed exploitation status.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| microsoft | office | 2010; 2013; 2016 |
Multiple CVSS Assessments
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
References
Weakness Type
No specific CWE has been assigned to CVE-2021-27059 in the NVD database. The vulnerability involves an unspecified flaw in Microsoft Office that enables remote code execution, though the precise weakness category has not been formally classified.
Impact Analysis
CVE-2021-27059 carries a CVSS 3.1 score of 7.6 (HIGH), indicating a significant security threat for organizations using affected Microsoft Office versions. The vulnerability is exploitable over the network but requires high attack complexity and high privileges, along with user interaction to trigger. The scope is changed, meaning successful exploitation can affect resources beyond the vulnerable Office component. Confidentiality (High): an attacker can gain full access to sensitive data. Integrity (High): complete modification of files, data, and configurations is possible. Availability (High): full disruption of the affected application and potentially other system resources can occur. Although the high attack complexity and privilege requirements somewhat limit widespread exploitation, the confirmed active exploitation in the CISA KEV catalog and the changed scope elevate the overall risk significantly.
Exploit Maturity
CVE-2021-27059 is confirmed as actively exploited through its inclusion in the CISA Known Exploited Vulnerabilities catalog, with a remediation deadline of 2021-11-17. The EPSS score of 2.05% (83.6th percentile) indicates a notable probability of exploitation. No public exploit code has been identified in the available references, suggesting that exploitation may be limited to more sophisticated threat actors with access to private exploit development. Ransomware usage has not been associated with this vulnerability. Despite the lack of public exploits, the confirmed active exploitation status means organizations should treat this as a high-priority remediation item.
Remediation
- Apply vendor patches immediately as mandated by CISA KEV: Apply updates per vendor instructions. Install the latest security update from the Microsoft Security Response Center.
- Verify that all instances of Microsoft Office 2010, 2013, and 2016 have been updated to the latest patched versions across the organization.
- As an interim mitigation, implement application-level controls to restrict Office from loading untrusted content. Configure Protected View and disable macros for documents from external sources through group policy settings.
- Deploy email and web security gateways to filter potentially malicious Office documents before they reach end users. Implement attachment sandboxing for Office file types from untrusted senders.
- Monitor endpoint detection and response (EDR) solutions for anomalous behavior from Office applications, including unexpected network connections, suspicious child process creation, and unusual file system modifications that may indicate exploitation attempts.
Technical Details
CVE-2021-27059 is a remote code execution vulnerability in Microsoft Office affecting versions 2010, 2013, and 2016. While the specific technical mechanism has not been publicly detailed, the vulnerability allows attackers to execute arbitrary code in the context of the affected Office process. The CVSS vector (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H) reveals several noteworthy characteristics: exploitation occurs over the network with high attack complexity, requires high privileges, and needs user interaction. The changed scope metric is particularly significant, indicating that the vulnerability can affect resources beyond the immediate Office application, potentially impacting the underlying operating system or other applications running in the user's context. The combination of high privileges required and high attack complexity suggests the vulnerability involves a multi-step exploitation process that requires specific preconditions or configuration states to trigger successfully.
Frequently Asked Questions
Is CVE-2021-27059 being actively exploited?
Yes. CVE-2021-27059 is listed in the CISA Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies were required to remediate this vulnerability by 2021-11-17. No public exploit code has been identified, but the EPSS score of 2.05% (83.6th percentile) indicates a notable exploitation probability.
What products are affected by CVE-2021-27059?
CVE-2021-27059 affects Microsoft Office versions 2010, 2013, and 2016. Organizations running any of these Office versions should verify that all instances have been updated with the latest security patches.
How do I fix CVE-2021-27059?
Apply updates per vendor instructions by installing the latest Microsoft security update for all affected Office versions. As interim measures, enable Protected View, disable macros from external sources, and implement email filtering to block suspicious Office documents. Monitor for anomalous Office application behavior through endpoint detection tools.
How severe is CVE-2021-27059?
CVE-2021-27059 has a CVSS 3.1 score of 7.6 (HIGH) with full impact on confidentiality, integrity, and availability and a changed scope. While the high attack complexity and privilege requirements provide some mitigation, its confirmed active exploitation in the CISA KEV catalog makes it a high-priority vulnerability requiring prompt remediation.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.