Impact
Untrusted pointer dereference in Microsoft Office Excel allows an attacker who can supply a crafted spreadsheet to execute arbitrary code on the victim’s machine. The weakness is identified as CWE-822 and carries a CVSS score of 7.8, indicating a high risk to confidentiality and integrity when an authorized user opens a malicious file.
Affected Systems
Affected suppliers include Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Office Online Server. Version details are not listed, so the vulnerability applies to the current releases of these products.
Risk and Exploitability
The vulnerability is local in nature; an attacker must provide a malicious Excel file that a user opens or processes. Because it requires local user interaction, the EPSS score of less than 1% reflects a low probability of currently observed exploitation, and the vulnerability is not present in the CISA KEV catalog. Nevertheless, the high CVSS score means that once a user opens a weaponized file, the attacker could achieve full code execution on that system. The likelihood of exploitation is dominated by user behavior and trust of file sources.
OpenCVE Enrichment