Impact
An out-of-bounds read flaw in Microsoft Office Excel permits a local attacker to read data beyond the intended buffer, potentially exposing sensitive memory contents or files accessed by Excel. This weakness, identified as CWE-125, allows disclosure of confidential information without granting code execution or system takeover capabilities.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Microsoft Office Online Server. No specific version ranges are given, so the entire product lines listed are potentially impacted.
Risk and Exploitability
The CVSS score of 6.1 indicates medium severity, while an EPSS score of less than 1% suggests a low likelihood of exploitation today. The vulnerability is not currently in the CISA KEV catalog. Exploitation requires local access to the target system and a crafted workbook or document; the description does not indicate a remote exploitation path. Consequently, the threat is limited to users who can run Excel files on the affected machine, and the risk primarily involves confidential data exposure rather than remote code execution.
OpenCVE Enrichment