Impact
Buffer over‑read in Microsoft Office Excel permits an unauthorized attacker to execute arbitrary code locally on the victim’s computer. The flaw arises when Excel processes specially crafted input and is a classic instance of CWE‑126, where improper bounds checking causes the program to read beyond the intended memory region. If successfully exploited, the attacker can compromise confidentiality, integrity, and availability of the affected system because the execution occurs with the permissions of the currently logged user.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 2021, Microsoft Office 2024, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Office Online Server.
Risk and Exploitability
The vulnerability has a CVSS score of 7.8, indicating high severity, while the EPSS score is below 1%, suggesting a low probability of exploitation at present. It is not listed in CISA’s KEV catalog. The likely attack vector involves delivering a malicious Office document that, when opened by a user, triggers the over‑read and results in local code execution. No elevated privileges or other preconditions are mentioned in the description, implying that any user opening the crafted file can be impacted.
OpenCVE Enrichment