PatchSiren

PatchSiren cyber security CVE debrief

CVE-2021-42293 Microsoft CVE debrief

Microsoft Jet Red Database Engine and Access Connectivity Engine Elevation of Privilege Vulnerability

Vendor
Microsoft
Product
Microsoft Office LTSC 2021
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2021-12-15
Original CVE updated
2026-05-19
Advisory published
2021-12-15
Advisory updated
2026-05-19

Who should care

Organizations running Microsoft Office or Microsoft 365 Apps with Jet Red Database Engine or Access Connectivity Engine components, particularly those processing untrusted database files or operating in multi-user environments where privilege escalation could impact system availability.

Technical summary

CVE-2021-42293 is an elevation of privilege vulnerability affecting the Microsoft Jet Red Database Engine and Access Connectivity Engine components. The vulnerability has a CVSS 3.1 score of 6.5 (MEDIUM severity) with an attack vector of network-accessible, low attack complexity, and requires low privileges. The vulnerability impacts availability (HIGH) with no direct impact to confidentiality or integrity. Affected products include Microsoft 365 Apps (Enterprise x64/x86), Office 2013 SP1 (x64/x86/RT), Office 2016 (x64/x86), Office 2019 (x64/x86), and Office LTSC 2021 (x64/x86). Microsoft has released security updates to address this vulnerability. Organizations should prioritize patching based on their use of Jet/ACE database components in Office applications.

Defensive priority

medium

Recommended defensive actions

  • Apply Microsoft security updates per vendor advisory
  • Review Microsoft Security Response Center guidance for CVE-2021-42293
  • Validate Office and 365 Apps installations are patched
  • Monitor for anomalous database engine activity in enterprise environments

Evidence notes

CVE published 2021-12-15. Modified 2026-05-19. CVSS 6.5 (MEDIUM). Not in CISA KEV.

Sources and references

Verified primary and authoritative sources

  • CVE-2021-42293 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2021-42293

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2021-42293 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2021-42293

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.