CVE-2021-42292
Microsoft Excel Security Feature Bypass Vulnerability
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- October 12, 2021
- Published Date
- November 10, 2021
- Last Updated
- February 04, 2025
- Vendor
- Microsoft
- Product
- Microsoft Office 2019, Microsoft Office 2019 for Mac, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021, Microsoft Excel 2016, Microsoft Office 2016, Microsoft Excel 2013 Service Pack 1, Microsoft Office 2013 Service Pack 1
- Description
- Microsoft Excel Security Feature Bypass Vulnerability
CVSS Scores
CVSS v3.1
7.8 - HIGH
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
SSVC Information
- Exploitation
- active
- Technical Impact
- total
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2021-11-17 00:00:00 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
corelight/CVE-2021-42292
Type: github • Created: 2021-11-09 12:14:45 UTC • Stars: 18
A Zeek package to detect CVE-2021-42292, a Microsoft Excel local privilege escalation exploit.