Junglewise Threat Intelligence

CVE-2021-42292: Microsoft Excel Security Feature Bypass

CVE-2021-42292 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2021-11-17

Technologies: Microsoft Office, Microsoft Excel 2016, Microsoft Office LTSC 2021, Microsoft 365 Apps for Enterprise. Vendors: Microsoft.

Executive brief

A security feature bypass vulnerability in Microsoft Excel allows for arbitrary code execution. The flaw requires a user to open a specially crafted file, bypassing security restrictions to execute malicious code on the local system.

Affected products

  • Microsoft Excel 2013 Service Pack 1
  • Microsoft Excel 2016
  • Microsoft Excel 2019
  • Microsoft Office LTSC 2021
  • Microsoft 365 Apps for Enterprise

Timeline

  • 2021-11-09: disclosed: NVD Published Date
  • 2021-11-17: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-17: patched: Vendor advisory and patch information published
  • 2021-11-17: exploited: Reported as exploited in the wild

Related threats