Impact
Microsoft Office Excel contains a race condition resulting from concurrent execution using a shared resource with improper synchronization. The flaw allows an unauthorized attacker to execute code locally within Excel. This can be triggered by concurrent operations that access the shared resource, enabling the attacker to run code with the privileges of the logged‑in user, potentially leading to data breach, tampering, or service disruption.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Office Online Server. All released iterations of these products are potentially vulnerable; no specific version ranges are listed by Microsoft.
Risk and Exploitability
The CVSS score of 7.0 classifies this vulnerability as High severity, while the EPSS score of less than 1% indicates a very low likelihood of exploitation at this time. The flaw is not listed in the CISA KEV catalog. Exploitation requires a local, running instance of Excel and an attacker to trigger the race condition, likely by opening a specially crafted workbook or macro that manipulates the shared resource concurrently. Based on the description, the attack vector is inferred to be local, and the resulting impact is confined to the privileges of the logged‑in user.
OpenCVE Enrichment