Cyber Resilience

CVE-2021-27059

Microsoft Office 2010 … 2016

CISA KEVActive ExploitationEUVD Exploited
Published
11 March 2021
Modified
30 October 2025
KEV Added
03 November 2021
Patch / advisory
CVSS Score v3.1 7.6
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
EPSS Score 0.032 87th percentile
Risk Priority 78 floored blend · peak EPSS

Summary

CVE-2021-27059 is a high-severity an unspecified weakness vulnerability in Microsoft Office. Its CVSS base score is 7.6 (High).

Operationally, ranked in the top 13% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

CVE-2021-27059 is a remote code execution vulnerability affecting Microsoft Office. It carries a CVSS 3.1 base score of 7.6 with the vector AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H, indicating network-accessible exploitation that requires high attack complexity, high privileges, and user interaction while producing high impacts on confidentiality, integrity, and availability along with a scope change.

An attacker meeting the privilege and interaction prerequisites can leverage the flaw to execute arbitrary code on an affected system, potentially compromising the confidentiality, integrity, and availability of data across security boundaries.

Microsoft has published remediation guidance through its Security Response Center advisory, and the vulnerability appears in CISA's catalog of known exploited vulnerabilities, confirming real-world exploitation activity.

EU & UK References

Vulnerability Data

Microsoft Office Remote Code Execution Vulnerability

CWE(s)
KEV Date Added
03 November 2021

Related Threats

CVEs Like This One

CVE-2017-8570Same product: Microsoft Officeboth on KEV
CVE-2015-1642Same product: Microsoft Officeboth on KEV
CVE-2015-2545Same product: Microsoft Officeboth on KEV
CVE-2013-1331Same product: Microsoft Officeboth on KEV
CVE-2015-1770Same product: Microsoft Officeboth on KEV
CVE-2017-0261Same product: Microsoft Officeboth on KEV
CVE-2017-0262Same product: Microsoft Officeboth on KEV
CVE-2017-11882Same product: Microsoft Officeboth on KEV
CVE-2010-3333Same product: Microsoft Officeboth on KEV
CVE-2006-2492Same product: Microsoft Officeboth on KEV

Affected Assets

microsoft
office
2010, 2013, 2016

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References