Impact
Microsoft Office Excel contains an integer underflow flaw that lets an attacker wrap numeric values to execute arbitrary code with the privileges of the user who opens a crafted workbook. This vulnerability can compromise confidentiality, integrity, and availability on the affected workstation.
Affected Systems
The flaw affects Microsoft products including Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Office Online Server.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity vulnerability, while the EPSS score is not available, suggesting limited evidence of exploitation but not ruling it out. The flaw is not listed in the CISA KEV catalog. Attackers would need to provide a specially crafted Excel file to a local user; the user must open the file for execution to occur. Due to the local nature and requirement for user action, the likelihood of widespread exploitation is moderate, but the impact on an affected system is significant.
OpenCVE Enrichment