Impact
An integer underflow flaw in Microsoft Office Excel can be exploited by an attacker to execute arbitrary code locally on a victim’s machine. The vulnerability arises when a wraparound occurs during integer processing, leading to a heap‑based buffer overflow (CWE‑122) and an integer overflow (CWE‑191). If successfully triggered, the attacker can run code with the same privileges as the user, potentially compromising the entire system.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Microsoft Office Online Server are listed as affected, but specific version numbers are not provided in the CVE data.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity while the EPSS score of less than 1 % reflects a currently low probability of exploitation. The vulnerability is not present in the CISA KEV catalog, suggesting no widespread exploited instances have been reported. Attackers most likely need to supply a crafted workbook that a local user opens, so the attack vector is inferred to be local file execution rather than remote exploitation. Although the exploitation probability is low, the ability to gain full control of the system makes this a significant threat if used maliciously.
OpenCVE Enrichment