Impact
This vulnerability is an out-of-bounds read flaw that lets a local attacker read data that the application should not expose. The weakness is classified as CWE-125, are insufficient. No evidence of remote code execution or denial of service is provided, so the impact is confined to local knowledge gain of sensitive information stored inside or adjacent to Excel memory.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Office Online Server. No specific vulnerable version numbers are listed in the CNA data, so all current releases of these products are potentially impacted.
Risk and Exploitability
The CVSS score of 5.5 indicates a medium severity and the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability does not appear in CISA’s KEV a locally executed exploit would be needed to trigger the out-of-bounds read.
OpenCVE Enrichment