Impact
The vulnerability is a type‑confusion flaw (CWE‑843) in Microsoft Office Excel triggered when the application accesses a resource using an incompatible type. This misinterpretation allows an attacker to execute arbitrary code locally on the victim’s machine. The CVE description does not specify how the flaw is exploited, but the likely attack vector is inferred to be through a malicious document or macro that causes Excel to load or reference an object of an incorrect type. The effect is that code running within the context of Excel can persist or move from the application into the operating system.
Affected Systems
Affected Microsoft products include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021 and 2024, Microsoft Office LTSC for Mac 2021 and 2024, and Office Online Server. Affected version information is not specified in the CNA data, so administrators should verify version compatibility against the Microsoft update guide.
Risk and Exploitability
The CVSS score of 7.8 classifies this vulnerability as high severity. The EPSS score of less than 1% indicates a very low probability of exploitation in the near term, and the vulnerability is not listed in the CISA KEV catalog. The documented description indicates the flaw permits local code execution via type confusion, but the exact attack vector – such as whether it requires opening a specially crafted workbook, running malicious macros, or other preconditions – is not explicitly stated, so the risk assessment assumes a low- to moderate likelihood of successful exploitation pending further vendor guidance.
OpenCVE Enrichment