Impact
A race condition defined by CWE‑362 arising from improper synchronization during concurrent operations on a shared resource in Microsoft Office Excel permits an unauthorized user to execute arbitrary code on the local machine. The flaw surfaces when Excel processes multiple instances of the same resource, allowing the attacker to inject or modify code executed with the privileges of the active user, potentially leading to data compromise, tampering, or service disruption.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Office Online Server. All released iterations of these products are potentially vulnerable; no specific version ranges are listed by Microsoft.
Risk and Exploitability
The CVSS score of 7.0 classifies this vulnerability as High severity, while the EPSS score of less than 1% indicates a very low likelihood of exploitation at this time. The flaw is not listed in the CISA KEV catalog. Exploitation requires a local, running instance of Excel and an attacker to trigger the race condition, likely by opening a specially crafted workbook or macro that manipulates the shared resource concurrently. Based on the description, the attack vector is inferred to be local, and the resulting impact is confined to the privileges of the logged‑in user.
OpenCVE Enrichment