Executive brief
A security feature bypass vulnerability in Microsoft Excel allows for arbitrary code execution. The flaw requires a user to open a specially crafted file, bypassing security restrictions to execute malicious code on the local system.
Affected products
- Microsoft Excel 2013 Service Pack 1
- Microsoft Excel 2016
- Microsoft Excel 2019
- Microsoft Office LTSC 2021
- Microsoft 365 Apps for Enterprise
Timeline
- 2021-11-09: disclosed: NVD Published Date
- 2021-11-17: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-17: patched: Vendor advisory and patch information published
- 2021-11-17: exploited: Reported as exploited in the wild