First published: Wed Nov 10 2021(Updated: )
A security feature bypass vulnerability in Microsoft Excel would allow a local user to perform arbitrary code execution.
Credit: secure@microsoft.com secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft 365 Apps | ||
Microsoft Excel | =2013-sp1 | |
Microsoft Excel | =2013-sp1 | |
Microsoft Office | =2013-sp1 | |
Microsoft Office | =2013-sp1 | |
Microsoft Office | =2016 | |
Microsoft Office | =2019 | |
Microsoft Office | =2019 | |
Microsoft Office Long Term Servicing Channel | =2021 | |
Microsoft Office Long Term Servicing Channel Macos | =2021 | |
Microsoft Excel | =2013-sp1 | |
Microsoft Office | =2013-sp1 | |
Microsoft Office | ||
=2013-sp1 | ||
=2013-sp1 | ||
=2013-sp1 | ||
=2013-sp1 | ||
=2016 | ||
=2019 | ||
=2019 | ||
=2021 | ||
=2021 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-42292 is a security feature bypass vulnerability in Microsoft Excel.
CVE-2021-42292 allows a local user to perform arbitrary code execution in Microsoft Excel.
CVE-2021-42292 has a severity rating of 7.8 (high).
Versions of Microsoft Office including 365 Apps, Office 2013 SP1, Office 2016, Office 2019, and Office Long Term Servicing Channel 2021 on both Windows and macOS are affected by CVE-2021-42292.
To mitigate CVE-2021-42292, Microsoft has released security updates. It is recommended to install the latest updates for affected Microsoft Office versions.