Impact
Excelize, a Go library that handles Microsoft Excel spreadsheets, contains a decryption routine that does not perform sufficient structural and parameter validation before invoking its decryption engines. When a malformed OLE compound file with a seemingly valid EncryptionInfo stream is processed, the library’s standard or agile decryptors slice, index, allocate, or divide using attacker‑controlled values. This leads to a Go runtime panic. The panic propagates back to the calling program and terminates the process, providing the attacker with the ability to crash applications but not to execute arbitrary code or gain further access.
Affected Systems
The issue affects the qax-os:excelize library, specifically versions 2.3.1 through 2.11.0. Projects that import this library and use its Decrypt functions to process user‑supplied or remotely supplied Excel files are at risk. No patched release is available as of this review, so all affected deployments remain vulnerable until an update is published.
Risk and Exploitability
With a CVSS score of 7.5, the vulnerability is considered high severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, indicating that no large‑scale exploitation has been observed. The attack vector is inferred to be a local or remote file input; an attacker can supply a corrupted encrypted workbook to trigger the panic, thereby causing a denial of service. Since no arbitrary code execution or privilege escalation is achieved, the primary impact is process termination and downstream availability loss.
OpenCVE Enrichment