CVE-2021-42292
KEVmassSecurity Feature Bypass in Microsoft Excel Enables Arbitrary Code Execution
CISA: Microsoft Excel Security Feature Bypass
Microsoft Excel, a component of Microsoft Office, contains a security feature bypass (CWE-357, insufficient verification of data authenticity) that would allow a local user to achieve arbitrary code execution. The flaw is triggered when Excel fails to properly verify data authenticity, allowing a file handled by Excel to bypass one of its security features rather than being processed safely. Successful exploitation lets an attacker run arbitrary code in the context of the local user, typically requiring the user to open Excel content on their machine. Anyone running the affected Microsoft Office/Excel software is exposed; the source data does not specify affected version ranges or fixed builds. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-17, confirming in-the-wild exploitation, and it carries a high 43% EPSS probability of exploitation within 30 days (99th percentile), though no public proof-of-concept is known and ransomware use is unknown.
What to do: Apply Microsoft's security updates for Office/Excel addressing CVE-2021-42292 per vendor instructions (the November 2021 Patch Tuesday release; the source data does not list specific fixed versions, so check Microsoft's advisory for affected builds). Federal agencies must patch by the CISA KEV required deadline. Until patched, exercise caution opening Excel files from untrusted or internet-sourced locations, since exploitation requires local user interaction.
| Microsoft Office (Excel) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft Excel Security Feature Bypass Vulnerability
- Affected
- Microsoft Office
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- 365 apps, excel, office, office 2016, office 2019, office 2021
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H