CVE-2021-42292High· 7.8▾ Abyssal⚠ Exploited in the wildPoC availableMicrosoft Excel Security Feature Bypass Vulnerability
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 42.9 · likelihood 8.6 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Aug 20.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Dec 1, 2021
Last analysed / modified upstream
43%
1 GitHub repo
Added to the CISA catalog on Nov 17, 2021. Federal remediation due Dec 1, 2021. View catalog ↗
Microsoft Excel Security Feature Bypass Vulnerability
365_appsexcel = 2013excel = 2016office = 2013office = 2019office_2016office_2019office_2021Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-21509High· 7.8Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
CVE-2021-38646High· 7.8Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
CVE-2026-85880High· 7.8Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
CVE-2026-81963High· 7.8Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
CVE-2026-85875Medium· 5.5Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-83951Medium· 5.5Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.