Impact
The vulnerability is an out‑of‑bounds read in Microsoft Office Excel that allows an unauthorized attacker to execute code locally. This flaw is a buffer underrun (CWE‑125). The primary impact is local code execution, allowing arbitrary commands to run on the victim machine.
Affected Systems
Affected systems include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Office Online Server. No specific version ranges are provided, so all current releases of these products are considered vulnerable until the update is applied.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, while the EPSS score of less than 1% suggests a very low likelihood of active exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to deliver a malicious spreadsheet file to a target user; the attack vector is likely user interaction. The code would execute locally with the privileges of the user who opens the file (inferred; not explicitly stated in the description).
OpenCVE Enrichment