Impact
A heap‑based buffer overflow in Microsoft Office Excel allows an attacker to execute arbitrary code locally when a specially crafted workbook is opened. The flaw, identified as CWE‑122, can enable the attacker to read, modify, or delete data on the host and to launch additional attacks from the compromised machine.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Microsoft Office Online Server.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, while the EPSS score of less than 1% and absence from the CISA KEV catalog suggest a low likelihood of exploitation. Based on the description, it is inferred that an attacker must deliver a malicious workbook to a user, typically via phishing or social engineering, and persuade that user to open the file. If successful, local code execution could be leveraged to compromise confidential data, sabotage services, or use the host as a pivot point into the network.
OpenCVE Enrichment