Security readout for executives and security teams
Plain-English summary
This is a medium-severity Microsoft Excel and Office information disclosure issue. A local low-privileged user could potentially expose confidential information. Sources do not describe the specific data exposed or exploitation mechanics. Treat it as a patching priority for systems handling sensitive documents or shared-user workloads.
Executive priority
Schedule remediation through normal vulnerability management, with faster handling for sensitive or shared systems. This is not currently supported by sources as an emergency active-exploitation issue.
Technical view
CVSS 3.1 vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N indicates local, low-complexity, low-privilege exploitation with high confidentiality impact and no integrity or availability impact. Affected products include Excel/Office 2013 SP1, 2016, Office 2019, Microsoft 365 Apps for Enterprise, Office Online Server, and Office Web Apps Server 2013 SP1.
Likely exposure
Exposure is likely on endpoints or servers running the listed Microsoft Office, Excel, Office Online Server, or Office Web Apps Server versions without the applicable Microsoft update.
Exploitation context
The source bundle marks KEV as false and exploit maturity as unproven. No cited source reports active exploitation. The local attack vector means this is most relevant where attackers already have low-privileged access to an affected host.
Researcher notes
The public bundle provides limited technical detail beyond CVSS and affected product data. Avoid assuming document-opening, remote exploitation, or specific leaked data without Microsoft advisory details or additional validated sources.
Mitigation direction
- Apply the Microsoft security update referenced by the MSRC advisory.
- Prioritize shared systems and devices processing sensitive spreadsheets.
- Check Microsoft guidance for product-specific update channels and KB details.
- Retire unsupported Office or server versions where patching is unavailable.
Validation and detection
- Inventory installed Microsoft Office, Excel, Office Online Server, and Office Web Apps versions.
- Confirm affected assets are at or beyond Microsoft’s fixed build level.
- Review vulnerability scanner results for CVE-2021-31174 after patch deployment.
- Verify shared or multi-user hosts are included in remediation scope.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2021-31174 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Medium
- CVSS
- 5.5 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C1.83.6Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
5.5MediumVector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
Source materials
- CVE List V5 sourceCVE List V5
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-31174CVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
