LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-38646: Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 28, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Apr 18, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-38646 to its Known Exploited Vulnerabilities catalog on Mar 28, 2022, with a federal patch deadline of Apr 18, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Microsoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution.

CVE-2021-38646 is a remote code execution vulnerability in the Microsoft Office Access Connectivity Engine. An attacker who successfully exploits it can run code in the context of the affected Office process, which can lead to full compromise of the user account and further movement inside the environment. CISA notes that this vulnerability has been used by ransomware operators, so organizations that run Microsoft Office should treat it as a priority for inventory and patching. Confirm all version and update details against the current Microsoft advisory.

How it works

Public detail on the exact weakness class is limited; CISA describes it only as an unspecified vulnerability in the Access Connectivity Engine that allows remote code execution. In general terms for this product class, the engine is responsible for connecting Office applications to data sources. A crafted file or data stream that the engine processes can trigger the flaw, letting the attacker execute arbitrary code with the privileges of the logged-on user or the Office process.

Exploitation typically requires the victim to open or otherwise process a malicious Office-related file or connection. No public exploit mechanics beyond the remote-code-execution outcome are provided in the given facts, so defenders should assume a standard Office document or data-connectivity attack path and verify the precise trigger conditions in Microsoft’s advisory.

Am I affected? How to find it in your systems

Microsoft Office is commonly installed on Windows endpoints used by knowledge workers, finance, and administrative staff; the Access Connectivity Engine is present in many standard Office deployments even when Access itself is not heavily used. Inventory every Windows workstation and VDI image that has Microsoft Office installed.

Because the CWE is unspecified, treat any unpatched Office installation that includes the Access Connectivity Engine as potentially vulnerable until the vendor advisory confirms otherwise.

How to remediate

The primary remediation is to apply the security updates Microsoft released for this vulnerability. Follow the vendor instructions exactly: deploy the appropriate Office update channel package (Microsoft 365 Apps, Office LTSC, or perpetual-license updates) through your normal patch-management process and verify successful installation.

If you can't patch immediately

When immediate patching is blocked by change windows or compatibility testing, apply compensating controls to reduce exposure:

These measures lower risk but do not replace the vendor update; schedule patching as soon as possible.

If your data may have been exposed

Actively exploited vulnerabilities, especially those with confirmed ransomware use, frequently precede data theft or encryption events. If you discover evidence of exploitation or have unpatched systems that processed untrusted files, initiate incident-response procedures: isolate affected hosts, preserve memory and disk images, and hunt for persistence and lateral movement. As a quick external check, users can run a free exposure scan of their work email addresses against known breach datasets to see whether credentials or personal data have already appeared in public dumps, then reset any compromised passwords and enable phishing-resistant MFA.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Office
Added to CISA KEVMar 28, 2022
Federal patch deadlineApr 18, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities