Impact
A type‑confusion flaw in Microsoft Office Excel allows an attacker to execute arbitrary code on the local machine. The vulnerability occurs when the application accesses an object of an incompatible type, letting malicious input be interpreted incorrectly. Because the code runs with the privileges of the user who opens the document, an attacker can compromise confidentiality, integrity, and availability of the affected system. The flaw is identified as CWE‑843.
Affected Systems
The affected products include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Microsoft Office Online Server. Specific patched versions are not listed, so all current releases of these products may be vulnerable.
Risk and Exploitability
The CVSS score of 7.8 signals a high severity vulnerability, while the EPSS score of less than 1% indicates a very low present exploitation probability. The vulnerability is not in the CISA KEV catalog, meaning no widespread exploitation has been reported. The attack vector most likely requires a user to open a malicious Office document locally, as the flaw is triggered when Excel parses the file. If exploited, the attacker gains local code execution with the privileges of the user opening the file.
OpenCVE Enrichment