Impact
The flaw is an out‑of‑bounds read in Microsoft Office Excel that allows an attacker with local access to read memory belonging to another object, potentially exposing sensitive data on the victim’s system and compromising confidentiality. This weakness is a classic out‑of‑bounds read identified as CWE‑125.
Affected Systems
The vulnerability affects Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Office Online Server. Specific version numbers are not listed in the advisory, so any assembly of the named products that lacks the official patch should be viewed as potentially vulnerable.
Risk and Exploitability
The CVSS base score of 7.1 indicates a high impact on confidentiality, while the exploitation complexity is moderate. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, suggesting that public exploits may not yet exist. The likely attack vector is local, requiring the attacker to supply malicious input or a workbook that triggers the out‑of‑bounds read; this inference is based on the nature of the defect.
OpenCVE Enrichment