Microsoft Office Gets Patched for 4 Vulnerabilities That Could Impact User Security: Check Point Research

Check Point Research said the issues existed in the MSGraph component that is a part of almost all Microsoft Office products.

Advertisement
By Jagmeet Singh | Updated: 8 June 2021 19:19 IST
Highlights
  • Microsoft Office was found to have the four vulnerabilities
  • Three of them were fixed last month
  • Microsoft Office users could be targeted through a malicious document

Microsoft has just patched the last vulnerability

Photo Credit: Reuters

Microsoft has patched as many as four vulnerabilities in its Office suite that includes Word, Excel, PowerPoint, Outlook as well as Office Web, Check Point Research said on Tuesday. These vulnerabilities could allow an attacker to impact users through malicious Office documents. The cybersecurity firm identified the security loopholes using an automated software technique called “fuzzing” and reported them to Microsoft in February. While three of the vulnerabilities were fixed last month, the company was able to patch the last one earlier on Tuesday. Users are recommended to update the Microsoft Office suite on their desktops and laptops.

Check Point Research said that the loopholes existed in the MSGraph component that is a part of Microsoft Office products including Word, Outlook, PowerPoint, and Excel, among others. The code that the researchers examined and found to be impacted by the vulnerabilities existed since at least the Office 2003 release launched in August 2003.

Advertisement

“To our knowledge, this component has not received too much attention from the security community until now, making it a fertile ground for bugs,” the Check Point Research noted in a blog post.

The researchers used the “fuzzing” technique to exploit the vulnerabilities using automated software. By using the technique, it was found that most of the Microsoft Office products were vulnerable to attacks using malicious code. This could be delivered to users through a specially crafted Word document in .docx format, Outlook Email in .eml, or an Excel spreadsheet in the .xls format.

Advertisement

“We learned that the vulnerabilities are due to parsing mistakes made in legacy code,” said Yaniv Balmas, Head of Cyber Research at Check Point Software, in a prepared statement. One of the primary learnings from our research is that legacy code continues to be a weak link in the security chain, especially in complex software like Microsoft Office.”

The researchers noted that there could be multiple attack vectors, and the simplest one would be when a victim downloads a malicious .xls file.

Advertisement

Check Point Research said that it disclosed the four vulnerabilities to Microsoft on February 28. Three of these that are classified as CVE-2021-31174, CVE-2021-31178, and CVE-2021-31179 were patched by the software giant on May 11, whereas the last one that is identified as CVE-2021-31939 was fixed on Tuesday.

The researchers at Check Point Research believe that while Microsoft has fixed the four vulnerabilities, there could be some others that may impact users. It is, therefore, recommended to install the latest Microsoft Office suite. Windows 10 users can specifically install the update by going to Settings > Update & security > Windows Update.


Interested in cryptocurrency? We discuss all things crypto with WazirX CEO Nischal Shetty and WeekendInvesting founder Alok Jain on Orbital, the Gadgets 360 podcast. Orbital is available on Apple Podcasts, Google Podcasts, Spotify, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Vivo V70 Lite 5G Silently Launched in Select Markets With These Features
  2. OnePlus Could Launch a New Budget Smartphone Lineup in India Soon
  3. Samsung Galaxy S27 Pro's Battery May Match the One on the Galaxy S26 Ultra
  4. Asus Dawn 7 Pro Series Launched With AMD Ryzen AI Chip, Two Display Options
  5. iQOO Neo 12 Tipped to Offer Major Display Upgrade Over Predecessor
  6. Redmi Turbo 5 Confirmed to Launch in India With This Rear Camera Setup
  7. WhatsApp Users on iOS Are Finally Getting Access to This Useful Feature
  8. New Leak Shows Us What Apple's Foldable iPhone Might Look Like
  9. Vivo X300 FE, iQOO 15R and More Discounted During Amazon Mega Deal Days Sale
  10. Samsung Galaxy Watch Ultra 2, Watch 9 Visit China's 3C Ahead of Launch
  1. Samsung Galaxy S26 FE Said to Ditch Matte Finish for a Glossy Rear Panel
  2. OnePlus N Series Tipped to Launch in India Next Month, Could Be More Affordable Than the OnePlus Nord CE 6 Lite
  3. Vivo Y31s 5G Launched With Snapdragon 4 Gen 2 Chip, 6,500mAh Battery: Price, Specifications
  4. Chinese Court Classifies Bitcoin as Property in Case Involving 107 BTC Theft
  5. Resident Evil Veronica Revealed at Summer Game Fest; Launch Set for 2027
  6. iQOO Neo 12 Said to Bring Major Display Upgrade With Up to 185Hz Refresh Rate
  7. Samsung Galaxy Watch Ultra 2, Galaxy Watch 9 Clear Key Regulatory Hurdle Ahead of Anticipated Launch
  8. Microsoft Reportedly Working on Shared Audio Feature on Windows 11 Alongside Tweaked Widgets
  9. WhatsApp Multi-Account Support on iOS Reportedly Rolling Out to More Users
  10. HTX Delists USD1 Stablecoin, Asks World Liberty Financial to Reverse Freeze on Exchange's Addresses
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.