Impact
The vulnerability is an integer underflow in Microsoft Excel that can be triggered by an attacker with a crafted workbook. The resulting wraparound can allow the attacker to execute arbitrary code locally on the victim’s machine. This flaw provides the attacker with the same privileges as the logged‑in user, potentially enabling full compromise of the affected system.
Affected Systems
Affected vendors and products include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Office Online Server. The description does not list specific version constraints beyond the product names.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. The EPSS score is not reported, and the vulnerability is not present in the CISA KEV catalog, suggesting no known mass exploitation yet. The likely attack vector requires an attacker to distribute a malicious workbook or document to a user, often via phishing or untrusted sharing. Once opened, local code execution can occur as the current user, enabling full system compromise if unpatched.
OpenCVE Enrichment