Impact
A heap‑based buffer overflow exists in Microsoft Office Excel that allows an unauthorized user to execute code locally. The flaw is categorized as CWE‑122. Successful exploitation results in arbitrary code execution with the privileges of the logged‑in user, compromising confidentiality, integrity, and availability of the affected system.
Affected Systems
Affected products include Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, Office Online Server, and Microsoft 365 Apps for Enterprise. The CVE payload does not provide version‑specific details, so the scope of affected versions remains unspecified.
Risk and Exploitability
With a CVSS score of 7.8, the vulnerability is rated high severity, but its EPSS score is below 1%, indicating a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the most likely attack vector is one in which an attacker delivers a malicious Excel workbook to a user, and the attacker exploits the buffer overflow when the workbook is opened, resulting in code execution with the privileges of the logged‑in user. Because the issue is a heap‑based overflow, it typically requires the file to be opened or data to be imported rather than exploitation through a remote network interface.
OpenCVE Enrichment