Impact
A use‑after‑free flaw in Microsoft Office Excel lets an attacker run arbitrary code on a victim’s machine. The vulnerability can be exploited when a controlled Excel file is opened or processed locally, allowing execution under the current user’s privileges and potentially compromising the confidentiality, integrity, and availability of the system. The weakness is identified as a classic use‑after‑free condition (CWE‑416).
Affected Systems
The affected products are Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Microsoft Office Online Server. No specific version numbers are listed, so all current releases of these products are considered vulnerable until the vendor issue is addressed.
Risk and Exploitability
The CVSS score of 7.8 reflects substantial impact, while the EPSS score of less than 1 % indicates a very low probability of active exploitation at present. The vulnerability is not in the CISA KEV catalog. The likely attack vector is a malicious Office file that triggers the use‑after‑free when opened; an attacker would need to deliver or embed such a file on the targeted machine.
OpenCVE Enrichment