CVE-2021-27059
Microsoft Office 2010 … 2016
Raw vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:HSummary
CVE-2021-27059 is a high-severity an unspecified weakness vulnerability in Microsoft Office. Its CVSS base score is 7.6 (High).
Operationally, ranked in the top 13% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.
Deeper analysis AI-assisted summary
Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.
CVE-2021-27059 is a remote code execution vulnerability affecting Microsoft Office. It carries a CVSS 3.1 base score of 7.6 with the vector AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H, indicating network-accessible exploitation that requires high attack complexity, high privileges, and user interaction while producing high impacts on confidentiality, integrity, and availability along with a scope change.
An attacker meeting the privilege and interaction prerequisites can leverage the flaw to execute arbitrary code on an affected system, potentially compromising the confidentiality, integrity, and availability of data across security boundaries.
Microsoft has published remediation guidance through its Security Response Center advisory, and the vulnerability appears in CISA's catalog of known exploited vulnerabilities, confirming real-world exploitation activity.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2021-13830
Vulnerability Data
Microsoft Office Remote Code Execution Vulnerability
- CWE(s)
- KEV Date Added
- 03 November 2021
Related Threats
CVEs Like This One
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.