Impact
An out‑of‑bounds read flaw in Microsoft Office Excel enables an unauthorized local user to read memory data that should be protected, allowing disclosure of potentially confidential information. The weakness is classified as CWE‑125, a buffer overread condition. As a result, an attacker with local access to a system can extract sensitive information from the process memory without triggering higher‑level permissions or remote code execution.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Office 2019, Office 2021 LTSC, Office 2024 LTSC, the Mac variants of Office 2021 and 2024, Office 365 for Mac, and the Office Online Server. These applications span both Windows and macOS environments, covering desktop and server deployments. No affected-version information is available in the CVE data.
Risk and Exploitability
The CVSS base score is 5.5, indicating moderate severity. The EPSS score falls below 1%, suggesting that exploitation is unlikely at present, and the vulnerability is not listed in the CISA KEV catalogue. The likely attack vector is local: an attacker must have access to the user session or device to trigger the read. Because the issue is an information‑disclosure bug, it does not grant arbitrary code execution, but it could expose sensitive data to local attackers.
OpenCVE Enrichment