Impact
Microsoft Office Excel contains a numeric truncation error that allows an unauthorized attacker to execute code locally. This vulnerability can result in arbitrary local code execution with the privileges of the user who opens the file.
Affected Systems
This issue impacts Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Office Online Server. No specific affected version information is available for these products.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity level, while the EPSS score of < 1% suggests a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The description notes that a numeric truncation error in Excel can be leveraged to execute arbitrary code locally, but it does not specify a precise attack vector beyond that local execution is possible.
OpenCVE Enrichment