Impact
An integer underflow bug in Microsoft Office Excel allows an attacker to execute arbitrary code on a victim’s machine. The flaw is triggered by malformed data that causes a wraparound in an integer calculation, enabling the execution of malicious payloads. The result is an attacker gaining the same privileges as the user opening the spreadsheet and compromising confidentiality, integrity, and availability of the system.
Affected Systems
The vulnerability affects a broad range of Microsoft Office environments including Microsoft 365 Apps for Enterprise, Excel 2016, Office 2019, Office 365 for Mac, Office LTSC 2021 and 2024, Office LTSC for Mac 2021 and 2024, and Office Online Server. All listed editions are included regardless of platform specifics.
Risk and Exploitability
The severity score of 7.8 indicates a high impact vulnerability. Although the EPSS score is not available, the lack of KEV listing does not diminish the potential for exploitation. The exploit likely requires an attacker to create a malicious workbook or document that a victim opens. Once executed, the attacker can run code with the user's privileges. Users are advised to apply vendor patches as soon as available.
OpenCVE Enrichment