CVE-2021-42292highunder attack

CVE-2021-42292: high-severity vulnerability in Microsoft 365 Apps for Enterprise

Microsoft Excel Security Feature Bypass Vulnerability

Published · Updated

83Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 7.8epss 43%
from disclosure to weapon0 days
Published on NVDNov 10
1st PoCNov 9
CISA KEV+7d
exploitation probability
43%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
1 public exploit(s)
Action required by CISAfederal deadline: 2021-12-01

Apply updates per vendor instructions.

In short

Microsoft Excel has a security bypass flaw that allows an attacker to bypass built-in security protections through a specially crafted file. This weakness could let malicious content run without proper authorization.

Technical detail

A security feature bypass vulnerability in Microsoft Excel permits an attacker to circumvent protection mechanisms via a malformed or specially crafted spreadsheet. The attack requires user interaction (opening a malicious file), but upon successful exploitation, it can lead to unauthorized code execution or access to sensitive data within the user's context.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Microsoft Excel Security Feature Bypass Vulnerability
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.