ZeroHour

CVE-2021-42292

KEVmass

Security Feature Bypass in Microsoft Excel Enables Arbitrary Code Execution

CISA: Microsoft Excel Security Feature Bypass

CVSS 3.1
7.8 high
EPSS
43%p99
Published
()
KEV added
AI analysis

Microsoft Excel, a component of Microsoft Office, contains a security feature bypass (CWE-357, insufficient verification of data authenticity) that would allow a local user to achieve arbitrary code execution. The flaw is triggered when Excel fails to properly verify data authenticity, allowing a file handled by Excel to bypass one of its security features rather than being processed safely. Successful exploitation lets an attacker run arbitrary code in the context of the local user, typically requiring the user to open Excel content on their machine. Anyone running the affected Microsoft Office/Excel software is exposed; the source data does not specify affected version ranges or fixed builds. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-17, confirming in-the-wild exploitation, and it carries a high 43% EPSS probability of exploitation within 30 days (99th percentile), though no public proof-of-concept is known and ransomware use is unknown.

What to do: Apply Microsoft's security updates for Office/Excel addressing CVE-2021-42292 per vendor instructions (the November 2021 Patch Tuesday release; the source data does not list specific fixed versions, so check Microsoft's advisory for affected builds). Federal agencies must patch by the CISA KEV required deadline. Until patched, exercise caution opening Excel files from untrusted or internet-sourced locations, since exploitation requires local user interaction.

Affected
Microsoft Office (Excel)
Estimated exposure
masshundreds of millions of users (Excel is deployed on the vast majority of Windows endpoints worldwide) — Microsoft Office/Excel is one of the most widely installed desktop applications globally, with hundreds of millions of licensed users and near-universal presence on managed Windows endpoints, so the plausible exposed population is at the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Excel Security Feature Bypass Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Office
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
365 apps, excel, office, office 2016, office 2019, office 2021
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news