EXPOSURES › CVE-2021-42292
CVE-2021-42292
HIGH ⌖ ON CISA KEV · EXPLOITEDA local user can bypass Excel security features to execute arbitrary code.
CVE-2021-42292 allows local privilege escalation via arbitrary code execution in Excel, which is actively exploited in the wild. DIBs must ensure patching is immediate and verify that local user accounts are restricted to prevent exploitation. This is not a zero-day but is a high-embarrassment unpatched vulnerability.
Shame score — A known, actively exploited vulnerability in a widely deployed product that requires local user access to exploit, indicating a failure to patch a critical flaw.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A security feature bypass vulnerability in Microsoft Excel would allow a local user to perform arbitrary code execution.
"A security feature bypass vulnerability in Microsoft Excel would allow a local user to perform arbitrary code execution."
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |