Impact
The vulnerability is an untrusted pointer dereference in Microsoft Office Excel that permits a local attacker to read data from the process memory that should remain hidden. The flaw leads to a breach of confidentiality, exposing sensitive information to an unauthorized user. It is classified as CWE-822, indicating improper or missing security controls around information exposure.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Office Online Server. No specific version information is provided in the CNA data.
Risk and Exploitability
The CVSS score of 5.5 reflects moderate severity, while the EPSS score of less than 1% indicates a low likelihood of exploitation in the wild. It is not listed in CISA’s KEV catalog. The likely attack vector is local; an attacker must be able to trigger the pointer dereference, for example by opening a malicious Excel file on a victim’s machine. No remote code execution or privilege escalation is possible, so the overall risk is moderate and limited to systems that process compromised Excel documents.
OpenCVE Enrichment