Impact
Microsoft Office Excel contains a heap-based buffer overflow that can allow an unauthorized user to execute arbitrary code locally, potentially escalating privileges or compromising the infected system. The vulnerability is a classic example of a memory corruption flaw, classified as CWE-122, and could enable attackers to run arbitrary code once the affected application processes a crafted document or file.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Office Online Server. No specific version numbers are listed, so all current releases of the mentioned products are potentially susceptible until updated.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, but the EPSS score of less than 1% shows a low current exploitation probability. The vulnerability is not in CISA’s KEV catalog, suggesting it is not known to be widely exploited. The likely attack vector is local, requiring the user to open a malicious or influenced Excel document or file, after which arbitrary code can run with the same permissions as the user.
OpenCVE Enrichment