High
CVE-2022-21840
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
High
(1 user assessed)Moderate
(1 user assessed)Unknown
Unknown
Unknown
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Description
Microsoft Office Remote Code Execution Vulnerability.
Add Assessment
Ratings
-
Attacker ValueHigh
-
ExploitabilityMedium
Technical Analysis
Looks like this is your fairly typical maliciously crafted document exploit for Microsoft Office. These bugs are used all the time by APTs and other groups simply cause its relatively easy to convince people to open documents given the right context, and even though some people will be fairly vigilant, all it takes is compromising one user to get an initial foothold into a target network.
This bug appears to affect all Microsoft Office versions since 2013 up to and including the latest Microsoft Office online solutions and also including Microsoft Sharepoint Servers from 2013 onwards, meaning that it has quite a wide range of potential targets. User interaction is required though in the form of opening a malicious document,
Given the supposedly low complexity of exploiting this vulnerability combined with the wide range of target that it can exploit, I’d expect to see exploits for this vulnerability in the wild over the coming few months.
Would you also like to delete your Exploited in the Wild Report?
Delete Assessment Only Delete Assessment and Exploited in the Wild ReportGeneral Information
Vendors
- Microsoft
Products
- Microsoft SharePoint Enterprise Server,
- Microsoft SharePoint Server,
- Microsoft Office,
- Microsoft Office Online Server,
- Microsoft 365 Apps for Enterprise for 32-bit Systems,
- Microsoft 365 Apps for Enterprise for 64-bit Systems,
- Microsoft Office LTSC for Mac 2021,
- Microsoft Office LTSC 2021 for 64-bit editions,
- Microsoft Office LTSC 2021 for 32-bit editions,
- Microsoft SharePoint Server Subscription Edition,
- SharePoint Server Subscription Edition Language Pack,
- Microsoft Excel,
- Microsoft Office Web Apps,
- Microsoft SharePoint Foundation
References
Additional Info
Technical Analysis
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: