PatchSiren cyber security CVE debrief
CVE-2021-42293 Microsoft CVE debrief
Microsoft Jet Red Database Engine and Access Connectivity Engine Elevation of Privilege Vulnerability
- Vendor
- Microsoft
- Product
- Microsoft Office LTSC 2021
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2021-12-15
- Original CVE updated
- 2026-05-19
- Advisory published
- 2021-12-15
- Advisory updated
- 2026-05-19
Who should care
Organizations running Microsoft Office or Microsoft 365 Apps with Jet Red Database Engine or Access Connectivity Engine components, particularly those processing untrusted database files or operating in multi-user environments where privilege escalation could impact system availability.
Technical summary
CVE-2021-42293 is an elevation of privilege vulnerability affecting the Microsoft Jet Red Database Engine and Access Connectivity Engine components. The vulnerability has a CVSS 3.1 score of 6.5 (MEDIUM severity) with an attack vector of network-accessible, low attack complexity, and requires low privileges. The vulnerability impacts availability (HIGH) with no direct impact to confidentiality or integrity. Affected products include Microsoft 365 Apps (Enterprise x64/x86), Office 2013 SP1 (x64/x86/RT), Office 2016 (x64/x86), Office 2019 (x64/x86), and Office LTSC 2021 (x64/x86). Microsoft has released security updates to address this vulnerability. Organizations should prioritize patching based on their use of Jet/ACE database components in Office applications.
Defensive priority
medium
Recommended defensive actions
- Apply Microsoft security updates per vendor advisory
- Review Microsoft Security Response Center guidance for CVE-2021-42293
- Validate Office and 365 Apps installations are patched
- Monitor for anomalous database engine activity in enterprise environments
Evidence notes
CVE published 2021-12-15. Modified 2026-05-19. CVSS 6.5 (MEDIUM). Not in CISA KEV.
Sources and references
Verified primary and authoritative sources
-
CVE-2021-42293 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2021-42293
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2021-42293 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2021-42293
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-42293
[email protected] - Patch, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.