Microsoft Access
cpe:2.3:a:microsoft:access:*:*:*:*:*:*:*
A remote code execution vulnerability has been identified in Microsoft Access. This issue affects multiple versions of Microsoft Access, including the 2019 and 2021 LTSC releases, as well as Microsoft 365 Apps for Enterprise. The vulnerability arises from a heap-based buffer overflow, which could be exploited by sending a specially crafted email attachment that bypasses security measures and executes malicious code when opened. Notably, the Preview Pane does not pose an attack vector for this vulnerability.
Exploitation of this vulnerability allows for remote code execution on the affected system.
Users can apply the security update provided by Microsoft to address this vulnerability. This update is available through the Microsoft Update Catalog and via Click-to-Run for various Microsoft 365 and Office LTSC editions.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.