Impact
An out‑of‑bounds read in Microsoft Office Excel permits an unauthorized attacker, via a malicious spreadsheet, to execute code locally on the victim's machine. The flaw exploits a memory boundary error, allowing the attacker to instruct Excel to run arbitrary code, resulting in complete compromise of the system. This vulnerability is categorized as CWE‑125 and carries a CVSS score of 7.8.
Affected Systems
The flaw affects a broad range of Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, and Office 2019/2021/2024 installations, including long‑term servicing channel, and Office Online Server. Specific version numbers are not listed, so all current builds of these products are potentially vulnerable.
Risk and Exploitability
The CVSS score indicates moderate to high severity, while the EPSS score of less than 1% suggests a low exploitation probability. The vulnerability is not listed in the CISA KEV catalog, implying no known active exploitation. The attack vector is inferred to be remote, requiring the delivery of a crafted Excel file—commonly via email attachments or compromised websites—while the victim opens it.
OpenCVE Enrichment