### CVE-2024-21379
**Severity:** High
**CVSS Score:** 7.8/10  
**Vulnerability Type:** Microsoft Word Remote Code Execution Vulnerability  
**EPSS Probability:** 1.72%

---

## Description
Microsoft Word Remote Code Execution Vulnerability

## Metrics
- **CVSS Score:** 7.8/10
- **CVSS Vector:** CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- **EPSS Probability:** 1.72% (75.3th percentile)
  - Probability of exploitation in the next 30 days. [Learn more](https://www.first.org/epss/)

## Weakness Enumeration
- [CWE-190](https://cwe.mitre.org/data/definitions/190.html)

## Affected Software
| Vendor     | Product                                          | Versions         |
|------------|--------------------------------------------------|------------------|
| Microsoft  | 365 Apps                                        | All versions      |
| Microsoft  | Office                                          | 2019              |
| Microsoft  | Office Long Term Servicing Channel               | 2021              |
| Microsoft  | Word                                            | 2016              |

## References
- [Patch, Vendor Advisory](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21379)
- [Patch, Vendor Advisory](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21379)

## Timeline
- **Published:** Feb 13, 2024  
- **Last Modified:** Aug 10, 2026  
- **Status:** Modified

## Frequently Asked Questions
### What is CVE-2024-21379?
Microsoft Word Remote Code Execution Vulnerability

### How severe is CVE-2024-21379?
CVE-2024-21379 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 1.72% probability of exploitation in the next 30 days.

### How do I fix CVE-2024-21379?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also [run a Strix scan](https://app.strix.ai/) to test if your systems are affected.
