Impact
The flaw is a numeric truncation error in Microsoft Office Excel that allows an unauthorized attacker to execute arbitrary code on a local machine. This arises when Excel processes specific numeric values, enabling the attacker to invoke code with the privileges of the user who opens the affected workbook. The result is a potential compromise of confidentiality, integrity, and availability of the affected system.
Affected Systems
This vulnerability affects various Microsoft Office products, including Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Office Online Server. No specific affected version information is available for these products.
Risk and Exploitability
The CVSS score of 7.8 denotes high severity, while the EPSS score of < 1% indicates a very low probability of exploitation. The flaw is not listed in the CISA KEV catalog. Attackers would likely need to provide a malicious Excel file and convince a local user to open it; this inference is based on typical Excel exploitation patterns, as the CVE description itself does not specify how the payload is delivered.
OpenCVE Enrichment