{
  "id": "CVE-2021-42292",
  "url": "https://spydr.io/cve/CVE-2021-42292",
  "published": "2021-11-10T01:19:47.007Z",
  "modified": "2026-08-19T19:23:04.123Z",
  "score": 7.8,
  "severity": "high",
  "cvss_version": "3.1",
  "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
  "score_source": "microsoft.com",
  "epss": 0.43005,
  "epss_percentile": 0.98687,
  "exploited": true,
  "kev": {
    "added": "2021-11-17",
    "due": "2021-12-01",
    "action": "Apply updates per vendor instructions.",
    "ransomware": "Unknown",
    "name": "Microsoft Excel Security Feature Bypass",
    "notes": "https://nvd.nist.gov/vuln/detail/CVE-2021-42292"
  },
  "ssvc_exploitation": "active",
  "vendors": [
    "Microsoft"
  ],
  "products": [
    "Microsoft 365 Apps for Enterprise",
    "Microsoft Excel 2013 Service Pack 1",
    "Microsoft Excel 2016",
    "Microsoft Office 2013 Service Pack 1",
    "Microsoft Office 2016",
    "Microsoft Office 2019",
    "Microsoft Office 2019 for Mac",
    "Microsoft Office LTSC 2021",
    "Microsoft Office LTSC for Mac 2021"
  ],
  "cwes": [],
  "description": "Microsoft Excel Security Feature Bypass Vulnerability",
  "status": "Analyzed",
  "score_type": "Secondary",
  "scores": {
    "cvss_v40": null,
    "cvss_v31": 7.8,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42292",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ]
    },
    {
      "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-42292",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ]
    },
    {
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-42292",
      "tags": [
        "US Government Resource"
      ]
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2021-42292",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
