Impact
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. The read occurs beyond intended memory bounds, potentially allowing the attacker to reach arbitrary data and then run arbitrary code with the privileges of the logged‑in user. This flaw is classified as CWE‑125 and could result in full compromise of an unpatched system.
Affected Systems
Affected vendors and products include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Office Online Server. The provided data do not specify version constraints beyond these product names.
Risk and Exploitability
The CVSS score of 7.8 indicates a high‑severity vulnerability, while the EPSS score of less than 1% shows a very low but non‑zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog, suggesting no mass exploitation has been documented. The likely attack vector is inferred to involve the delivery of a malicious workbook or document to a user, often via phishing or untrusted sharing; once the file is opened, the local code execution can occur under the current user’s privileges, enabling potential system compromise if the system is not patched.
OpenCVE Enrichment