Microsoft Office Gets Patched for 4 Vulnerabilities That Could Impact User Security: Check Point Research

Check Point Research said the issues existed in the MSGraph component that is a part of almost all Microsoft Office products.

Advertisement
By Jagmeet Singh | Updated: 8 June 2021 19:19 IST
Highlights
  • Microsoft Office was found to have the four vulnerabilities
  • Three of them were fixed last month
  • Microsoft Office users could be targeted through a malicious document

Microsoft has just patched the last vulnerability

Photo Credit: Reuters

Microsoft has patched as many as four vulnerabilities in its Office suite that includes Word, Excel, PowerPoint, Outlook as well as Office Web, Check Point Research said on Tuesday. These vulnerabilities could allow an attacker to impact users through malicious Office documents. The cybersecurity firm identified the security loopholes using an automated software technique called “fuzzing” and reported them to Microsoft in February. While three of the vulnerabilities were fixed last month, the company was able to patch the last one earlier on Tuesday. Users are recommended to update the Microsoft Office suite on their desktops and laptops.

Check Point Research said that the loopholes existed in the MSGraph component that is a part of Microsoft Office products including Word, Outlook, PowerPoint, and Excel, among others. The code that the researchers examined and found to be impacted by the vulnerabilities existed since at least the Office 2003 release launched in August 2003.

“To our knowledge, this component has not received too much attention from the security community until now, making it a fertile ground for bugs,” the Check Point Research noted in a blog post.

Advertisement

The researchers used the “fuzzing” technique to exploit the vulnerabilities using automated software. By using the technique, it was found that most of the Microsoft Office products were vulnerable to attacks using malicious code. This could be delivered to users through a specially crafted Word document in .docx format, Outlook Email in .eml, or an Excel spreadsheet in the .xls format.

Advertisement

“We learned that the vulnerabilities are due to parsing mistakes made in legacy code,” said Yaniv Balmas, Head of Cyber Research at Check Point Software, in a prepared statement. One of the primary learnings from our research is that legacy code continues to be a weak link in the security chain, especially in complex software like Microsoft Office.”

The researchers noted that there could be multiple attack vectors, and the simplest one would be when a victim downloads a malicious .xls file.

Advertisement

Check Point Research said that it disclosed the four vulnerabilities to Microsoft on February 28. Three of these that are classified as CVE-2021-31174, CVE-2021-31178, and CVE-2021-31179 were patched by the software giant on May 11, whereas the last one that is identified as CVE-2021-31939 was fixed on Tuesday.

The researchers at Check Point Research believe that while Microsoft has fixed the four vulnerabilities, there could be some others that may impact users. It is, therefore, recommended to install the latest Microsoft Office suite. Windows 10 users can specifically install the update by going to Settings > Update & security > Windows Update.


Interested in cryptocurrency? We discuss all things crypto with WazirX CEO Nischal Shetty and WeekendInvesting founder Alok Jain on Orbital, the Gadgets 360 podcast. Orbital is available on Apple Podcasts, Google Podcasts, Spotify, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Google's Pixel Upgrade Program Lets You Get the Latest Model Every Year
  2. Here's When the Realme 16 Pro Series Will Launch in India
  3. OTT Releases This Week: Thamma, Mrs Deshpande, Raat Akeli Hai The Bansal Murders, and More
  4. Here's How Much The Redmi Note 15 5G Could Cost in India
  5. Redmi Pad 2 Pro 5G Will Launch in India Soon: See Expected Features
  6. Oppo Reno 15 Pro, Reno 15 Pro Max Global Variants Surface on Geekbench
  7. Samsung Announces Exynos 2600 as World's First 2nm Chipset
  8. Vivo X200T Tipped to Feature This Dimensity Chipset Ahead of India Launch
  9. Oppo Reno 15 Pro Mini Tipped to Launch as First Compact Reno Smartphone
  10. Samsung Galaxy Z Fold 8 May Offer These Notable Camera Upgrades
  1. Sony Announces Year-End Holiday Sale in India on PS5 Accessories, Games
  2. Xiaomi 17 Ultra Battery, Charging Specifications and Colourways Tipped Ahead of Launch
  3. Redmi Note 15 5G Price in India, Storage Configurations Tipped Ahead of January 6 Launch
  4. Little Hearts Streaming Now on Netflix: Know Everything About Plot, Cast, and More
  5. Crypto Traders Remain Cautious Amidst Tight Liquidity and Mixed Global Cues
  6. Oppo Reno 15 Pro Global Variant Reportedly Surface on Geekbench Alongside Reno 15 Pro Max
  7. Vivo X200T Key Specifications Tipped Ahead of India Launch; Could Feature Three 50-Megapixel Cameras
  8. Meta Reportedly Building Three New Generative AI Models With Focus on Image and Video Generation
  9. Google Pixel Upgrade Program Launched in India With Assured Buyback of Pixel 10 Series Models
  10. Intergalactic: The Heretic Prophet Targeting Mid-2027 Launch as Naughty Dog Orders Overtime: Report
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.