Impact
The flaw is a type‑confusion error (CWE-843) in Microsoft Office Excel where an attacker can supply a crafted resource that causes the application to process an incompatible type. This results in arbitrary code execution with the privileges of the user running Excel. Based on the description, it is inferred that the attacker gains the privileges of the user running Excel. The CVE description does not specify any additional control‑flow beyond local execution, and no further capabilities such as remote pivoting are documented.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Office Online Server are affected. The advisory does not list specific version ranges, so all current releases should be reviewed for the presence of the fix.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity while the EPSS value of less than 1% suggests a very low likelihood of widespread exploitation. The vulnerability is not included in CISA’s KEV catalog. The likely attack vector is inferred to be a malicious Office document that must be opened locally by a user; type‑confusion vulnerabilities typically require local file execution and no remote exploitation is documented.
OpenCVE Enrichment