Impact
A heap-based buffer overflow exists in Microsoft Office Excel, permitting an unauthorized user to execute arbitrary code locally. The flaw can compromise data confidentiality, integrity, and availability by allowing the attacker to run malicious payloads on the victim’s system. The weakness corresponds to CWE-122.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Office 2019, Office 365 for Mac, Office LTSC 2021 and 2024, Office LTSC for Mac versions 2021 and 2024, and Office Online Server. Users of any of these applications should verify whether they are running a build that pre-dates the included fix.
Risk and Exploitability
The CVSS score is 7.8, indicating high severity, while the EPSS score of less than 1% suggests a low probability of widespread exploitation at the moment. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local, likely through a malicious Excel file or document that the user opens or processes. Because the description notes that the attacker need not be privileged, any local user can subvert the system.
OpenCVE Enrichment