Impact
An out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. This flaw, categorized as CWE-125, restricts the impact to the local user context and does not provide remote code execution or privilege escalation.
Affected Systems
Affected are Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021 and 2024, Microsoft Office LTSC for Mac 2021 and 2024, and Office Online Server. Specific version ranges are not provided in the advisory, meaning any installation of the listed products could be vulnerable if not patched.
Risk and Exploitability
The CVSS score of 3.3 classifies this vulnerability as low severity. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a network-based local attacker who can cause or influence the vulnerable read operation, which suggests that the threat is mainly local or internal to the network. The impact is limited to information disclosure; there is no evidence of escalation, execution, or denial of service.
OpenCVE Enrichment