Impact
The CVE describes a use‑after‑free flaw in Microsoft Office Excel that allows an attacker to execute code locally on the victim’s machine. This can compromise the affected workstation or device by running arbitrary code with the privileges of the logged‑in user.
Affected Systems
Affected vendors and products include Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Office Online Server. Specific version information is not supplied, so all currently available releases of those products may be impacted.
Risk and Exploitability
The CVSS score of 7.8 classifies the flaw as high severity. The EPSS score of less than 1% indicates a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector requires local user interaction, such as opening a malicious Excel file; remote exploitation is not documented. While the likelihood of widespread exploitation is low, the potential impact remains significant for environments that allow users to open untrusted Office files.
OpenCVE Enrichment