cbcvebase.
CVE-2021-42292
published 2021-11-10

CVE-2021-42292: Microsoft Excel Security Feature Bypass Vulnerability

high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2021-12-01
Exploited in the wild
Microsoft Excel Security Feature Bypass Vulnerability

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftexcel
microsoftmicrosoft_365_apps_for_enterprise>= 16.0.1 < https://aka.ms/OfficeSecurityReleaseshttps://aka.ms/OfficeSecurityReleases
microsoftmicrosoft_excel_2013_service_pack_1>= 15.0.0.0 < 15.0.5397.100115.0.5397.1001
microsoftmicrosoft_excel_2016>= 16.0.0.0 < 16.0.5239.100116.0.5239.1001
microsoftmicrosoft_office_2013_service_pack_1>= 15.0.0 < 15.0.5397.100115.0.5397.1001
microsoftmicrosoft_office_2016>= 16.0.0 < 16.0.5239.100116.0.5239.1001
microsoftmicrosoft_office_2019>= 19.0.0 < https://aka.ms/OfficeSecurityReleaseshttps://aka.ms/OfficeSecurityReleases
microsoftmicrosoft_office_2019_for_mac>= 16.0.0 < 16.55.2111140016.55.21111400
microsoftmicrosoft_office_ltsc_2021>= 16.0.1 < https://aka.ms/OfficeSecurityReleaseshttps://aka.ms/OfficeSecurityReleases
microsoftmicrosoft_office_ltsc_for_mac_2021>= 16.0.1 < 16.55.2111140016.55.21111400
microsoftoffice
microsoftoffice
microsoftoffice
microsoftoffice_long_term_servicing_channel
msrcmicrosoft_365_apps_for_enterprise_for_32-bit_systems
msrcmicrosoft_365_apps_for_enterprise_for_64-bit_systems
msrcmicrosoft_excel_2013_rt_service_pack_1
msrcmicrosoft_excel_2013_service_pack_1
msrcmicrosoft_excel_2016
msrcmicrosoft_office_2013_rt_service_pack_1
msrcmicrosoft_office_2013_service_pack_1
msrcmicrosoft_office_2016
msrcmicrosoft_office_2019_for_32-bit_editions
msrcmicrosoft_office_2019_for_64-bit_editions
msrcmicrosoft_office_2019_for_mac

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vulncheck7.8HIGH
cisa7.8HIGH