Impact
An out‑of‑bounds read in Microsoft Office Excel enables an unauthorized local attacker to read memory beyond allocated limits (CWE‑125). This leads to local information disclosure; it does not grant remote code execution, privilege escalation, or denial of service.
Affected Systems
Affected are Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021 and 2024, Microsoft Office LTSC for Mac 2021 and 2024, and Office Online Server. Specific version ranges are not provided in the advisory, meaning any installation of the listed products could be vulnerable if not patched.
Risk and Exploitability
The CVSS score of 3.3 classifies this vulnerability as low severity. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an unauthorized local user who can trigger the vulnerable read operation, which suggests that the threat is mainly local or internal to the network. The impact is limited to information disclosure; there is no evidence of escalation, execution, or denial of service.
OpenCVE Enrichment