CVE-2021-42292: Microsoft Excel Security Feature Bypass Vulnerability
Published Nov 10, 2021
·Updated
A security feature bypass vulnerability in Microsoft Excel would allow a local user to perform arbitrary code execution.
Other sources
Microsoft Excel Security Feature Bypass Vulnerability
Affected Software
13 affected components
Microsoft Office
Microsoft 365 Apps
Microsoft Excel=2013-sp1
Microsoft Excel=2013-sp1
Microsoft Office=2013-sp1
Microsoft Office=2013-sp1
Microsoft Office=2016
Microsoft Office=2019
Microsoft Office Macos=2019
Microsoft Office Long Term Servicing Channel=2021
Microsoft Office Long Term Servicing Channel Macos=2021
Microsoft Excel=2013-sp1
Microsoft Office=2013-sp1
Remediation
Event History
Nov 10, 2021
CVE Published
via MITRE·12:47 AM
Data Sourced
via MITRE·12:47 AM
DescriptionSeverity
Data Sourced
via NVD·01:19 AM
RemedyDescriptionSeverityAffected Software
Nov 17, 2021
Known Exploited
via CISA·12:00 AM
Frequently Asked Questions
1
What is CVE-2021-42292?
CVE-2021-42292 is a security feature bypass vulnerability in Microsoft Excel.
2
How does CVE-2021-42292 affect Microsoft Excel?
CVE-2021-42292 allows a local user to perform arbitrary code execution in Microsoft Excel.
3
What is the severity of CVE-2021-42292?
CVE-2021-42292 has a severity rating of 7.8 (high).
4
What versions of Microsoft Office are affected by CVE-2021-42292?
Versions of Microsoft Office including 365 Apps, Office 2013 SP1, Office 2016, Office 2019, and Office Long Term Servicing Channel 2021 on both Windows and macOS are affected by CVE-2021-42292.
5
How can CVE-2021-42292 be fixed?
To mitigate CVE-2021-42292, Microsoft has released security updates. It is recommended to install the latest updates for affected Microsoft Office versions.