Impact
Microsoft Office Excel has a type confusion flaw (CWE-843) that allows an attacker to force the application to use an incompatible resource type via a crafted workbook, resulting in local code execution. The flaw requires the victim to open the malicious file; it does not rely on network interactions. The result is that arbitrary code can be run on the user's machine.
Affected Systems
Microsoft products affected include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021 and LTSC for Mac 2021 and LTSC for Mac 2024, and Office Online Server. The vulnerability is present across these Office families; specific version details are not listed beyond the product family.
Risk and Exploitability
The CVSS score of 7.8 categorizes this as a high‑severity flaw. The EPSS score is < 1% (0.00372), indicating a low probability of exploitation in the wild, and the flaw is not listed in the CISA KEV catalog. The likely attack vector privilege is required; the user must open a crafted file.
OpenCVE Enrichment