Impact
A use‑after‑free flaw in Microsoft Office Excel enables an attacker to run arbitrary code on the victim’s machine. The vulnerability can be triggered by opening a specially crafted document, allowing the attacker to gain full control over the device and compromise confidentiality, integrity, and availability. It is classified as CWE‑416, a use‑after‑free weakness.
Affected Systems
The flaw affects Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Office LTSC 2021, Office LTSC 2024, Office LTSC for Mac 2021, Office LTSC for Mac 2024, and Office Online Server. Version information is not enumerated beyond the product families, but any installation of these products is potentially susceptible.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, and while an EPSS score is not provided, the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires delivery of a malicious file and user action to open it, so the attack vector is likely user‑initiated. Given the local impact and high severity, the risk to enterprises remains significant.
OpenCVE Enrichment