Impact
The vulnerability exploits an out‑of‑bounds read in Microsoft Office Excel, allowing an unauthorized attacker to execute code locally. When Excel processes a crafted file it reads beyond the intended memory bounds, which can lead to arbitrary code execution under the user's privileges. This flaw is classified as CWE‑125 and can result in full system compromise if an unpatched system processes a malicious workbook.
Affected Systems
Affected vendors and products include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Office Online Server. The provided data do not specify version constraints beyond these product names.
Risk and Exploitability
The CVSS score of 7.8 indicates a high‑severity vulnerability, while the EPSS score of less than 1% shows a very low but non‑zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog, suggesting no mass exploitation has been documented. The likely attack vector is inferred to involve the delivery of a malicious workbook or document to a user, often via phishing or untrusted sharing; once the file is opened, the local code execution can occur under the current user’s privileges, enabling potential system compromise if the system is not patched.
OpenCVE Enrichment