CVE-2021-40481 is a remote code execution vulnerability affecting Microsoft Office Visio, as well as Microsoft 365 Apps and Office Long Term Servicing Channel. With a CVSS score of 7.8 (High), it allows an attacker to execute arbitrary code on a vulnerable system through user interaction, typically by tricking a user into opening a specially crafted Visio file. While not currently listed on CISA's KEV catalog or having public exploit code in Metasploit or ExploitDB, it has garnered some community discussion and media coverage, indicating awareness of the flaw. The vulnerability was addressed in Microsoft's October 2021 Patch Tuesday updates.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2019:*:*:*:*:*:*:* | ||
2021CPE matchmatch criteria | cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.