This Microsoft Patch Tuesday fixes a zero-day vulnerability in Excel that is being exploited by malicious actors.

See also: Microsoft releases the very affordable Surface Laptop SE
Zero-days, as defined by Microsoft, are bugs that are publicly disclosed without having official security updates that fix them.
The vulnerability, which has been designated CVE-2021-42292, is a high-severity security feature bypass that can be exploited locally by attackers, without the need for authentication, in low-sophistication attacks that do not require user interaction.
Microsoft also patched a second security flaw in Excel, used during the Tianfu Cup last month, a remote code execution bug dubbed CVE-2021-40442 that can be exploited by unauthenticated attackers.
See also: Microsoft Excel: How to create a dependent drop-down list
Fortunately, Microsoft says that the Windows Explorer preview pane is not an attack vector for the two bugs.
This means that successful exploitation requires the full opening of the malicious Excel files, rather than a simple click.

While the company released security updates for systems running Microsoft 365 Apps for Enterprise and Windows versions of Microsoft Office and Microsoft Excel, it failed to patch the vulnerabilities in macOS .
Mac users running macOS versions of Microsoft Office will need to wait a little longer for the CVE-2021-42292 patches.
“ The security update for Microsoft Office 2019 for Mac and Microsoft Office LTSC for Mac 2021 is not immediately available ,” Microsoft said . “ Updates will be released as soon as possible, and when they are available, customers will be notified by reviewing this CVE information. ”
The two bugs were discovered by security researchers from the Microsoft Threat Intelligence Center.
See also: Microsoft: New security updates cause Windows Server auth issues
Microsoft also warned administrators on Tuesday to immediately patch a high-severity Exchange Server vulnerability, known as CVE-2021-42321, which affects on-premises servers running Exchange Server 2016 and Exchange Server 2019.
As explained in the security advisory, successful exploitation could allow attackers to remotely execute code on vulnerable servers.
