CVE-2021-42292: high-severity vulnerability in Microsoft 365 Apps for Enterprise
Microsoft Excel Security Feature Bypass Vulnerability
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Apply updates per vendor instructions.
Microsoft Excel has a security bypass flaw that allows an attacker to bypass built-in security protections through a specially crafted file. This weakness could let malicious content run without proper authorization.
A security feature bypass vulnerability in Microsoft Excel permits an attacker to circumvent protection mechanisms via a malformed or specially crafted spreadsheet. The attack requires user interaction (opening a malicious file), but upon successful exploitation, it can lead to unauthorized code execution or access to sensitive data within the user's context.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.