CVE-2021-42292
Microsoft Office 2013 … 2019
Raw vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HSummary
CVE-2021-42292 is a high-severity an unspecified weakness vulnerability in Microsoft Office. Its CVSS base score is 7.8 (High).
Operationally, ranked in the top 2% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.
Deeper analysis AI-assisted summary
Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.
Microsoft Excel contains a security feature bypass vulnerability that allows an attacker to circumvent protections in the application. The flaw affects Microsoft Excel and carries a CVSS 3.1 base score of 7.8 with the vector AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, indicating local attack vector, low complexity, no privileges required, and required user interaction to achieve high impact on confidentiality, integrity, and availability.
An attacker can exploit the issue by supplying a specially crafted file that a user opens locally in Excel. Successful exploitation bypasses security controls and can lead to arbitrary code execution or other high-impact actions on the affected system without needing elevated privileges.
Microsoft has published guidance in its security advisory for CVE-2021-42292, and the vulnerability appears in CISA's catalog of known exploited vulnerabilities, confirming observed in-the-wild exploitation.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2021-29267
Vulnerability Data
Microsoft Excel Security Feature Bypass Vulnerability
- CWE(s)
- KEV Date Added
- 17 November 2021
Related Threats
CVEs Like This One
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.