PatchSiren

PatchSiren cyber security CVE debrief

CVE-2021-42296 Microsoft CVE debrief

A remote code execution vulnerability in Microsoft Word, rated HIGH severity (CVSS 7.8), was disclosed on November 10, 2021. The vulnerability requires local attack vector with user interaction—an attacker must convince a victim to open a maliciously crafted document. Successful exploitation yields high impact across confidentiality, integrity, and availability. Microsoft released patches and security guidance at the time of disclosure. The CVE record was last modified on May 19, 2026, indicating ongoing curation of affected product configurations.

Vendor
Microsoft
Product
Microsoft 365 Apps for Enterprise
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2021-11-10
Original CVE updated
2026-08-19
Advisory published
2021-11-10
Advisory updated
2026-08-19

Who should care

Organizations running Microsoft 365 Apps for Enterprise or Office LTSC 2021; security teams defending against document-based malware; incident responders investigating suspicious Word document activity.

Technical summary

CVE-2021-42296 is a remote code execution vulnerability in Microsoft Word with a CVSS 3.1 score of 7.8 (HIGH). The attack requires local access with user interaction—typically opening a malicious document. The vulnerability is rooted in improper control of code generation (CWE-94). Affected platforms include Microsoft 365 Apps for Enterprise and Office Long Term Servicing Channel 2021 on both x64 and x86 architectures. Microsoft issued patches and vendor advisories concurrent with the November 10, 2021 disclosure. The CVE record received a modification update on May 19, 2026, reflecting continued maintenance of product configuration data.

Defensive priority

HIGH

Recommended defensive actions

  • Apply Microsoft security updates for CVE-2021-42296 released November 2021.
  • Enable Microsoft Office Protected View and Application Guard to reduce attack surface from untrusted documents.
  • Restrict macro execution and block external content in Word documents via Group Policy or cloud security settings.
  • Train users to recognize and avoid opening unexpected or suspicious Word attachments.
  • Monitor for anomalous winword.exe child processes or suspicious document-based payload delivery attempts.

Evidence notes

CVE published 2021-11-10; modified 2026-05-19. CVSS 3.1 vector: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. Affected products include Microsoft 365 Apps for Enterprise (x64, x86) and Office LTSC 2021 (x64, x86). Weakness classified as CWE-94 (Improper Control of Generation of Code).

Sources and references

Verified primary and authoritative sources

  • CVE-2021-42296 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2021-42296

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2021-42296 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2021-42296

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.