PatchSiren cyber security CVE debrief
CVE-2021-43875 Microsoft CVE debrief
CVE-2021-43875 is a remote code execution vulnerability in Microsoft Office Graphics, published by Microsoft on December 15, 2021. The vulnerability carries a CVSS 3.1 score of 7.8 (HIGH severity) with an attack vector of local (AV:L), low attack complexity (AC:L), no privileges required (PR:N), and requires user interaction (UI:R). The vulnerability affects multiple Microsoft Office product lines including Microsoft 365 Apps for Enterprise (x64 and x86), Office 2019 (x64, x86, and macOS), and Office Long Term Servicing Channel 2021 (x64, x86, and macOS). The NVD entry was last modified on May 19, 2026, indicating ongoing curation of the record. Microsoft has released security updates to address this vulnerability, and organizations should apply these patches to affected Office installations. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, and no known ransomware campaign use has been documented.
- Vendor
- Microsoft
- Product
- Microsoft Office 2019
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2021-12-15
- Original CVE updated
- 2026-05-19
- Advisory published
- 2021-12-15
- Advisory updated
- 2026-05-19
Who should care
Organizations running Microsoft Office 2019, Microsoft 365 Apps for Enterprise, or Office LTSC 2021 on Windows or macOS endpoints. Security teams responsible for endpoint patch management and vulnerability remediation programs. IT administrators managing Office deployments in enterprise environments.
Technical summary
CVE-2021-43875 is a remote code execution vulnerability in Microsoft Office Graphics components. The vulnerability requires user interaction to trigger, typically through opening a maliciously crafted Office document. Successful exploitation could allow an attacker to execute arbitrary code in the context of the current user. The attack complexity is low, and the vulnerability impacts confidentiality, integrity, and availability (all rated HIGH). The affected attack surface spans multiple Office deployment channels including Microsoft 365 Apps for Enterprise, Office 2019, and Office Long Term Servicing Channel 2021 across Windows (x64/x86) and macOS platforms. Microsoft has issued security updates to remediate this vulnerability.
Defensive priority
HIGH
Recommended defensive actions
- Apply Microsoft security updates for CVE-2021-43875 to all affected Office installations
- Prioritize patching for systems running Microsoft 365 Apps for Enterprise, Office 2019, and Office LTSC 2021
- Verify patch deployment across both Windows (x64/x86) and macOS platforms
- Monitor Microsoft Security Response Center (MSRC) guidance for any additional mitigation measures
- Review endpoint detection and response (EDR) coverage for Office-related process execution anomalies
Evidence notes
CVE published 2021-12-15 per NVD and Microsoft security guidance. CVSS vector CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H from NVD. Affected products confirmed via NVD CPE criteria: Microsoft 365 Apps Enterprise, Office 2019, Office LTSC 2021 across x64, x86, and macOS platforms. Not in KEV per supplied enrichment data.
Official resources
-
CVE-2021-43875 CVE record
CVE.org
-
CVE-2021-43875 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Patch, Vendor Advisory
2021-12-15