Impact
Integer overflow or wraparound in Microsoft Excel can be triggered by an unauthorized attacker with no authentication, allowing arbitrary code to run locally on the affected host. The flaw arises from improper handling of signed integers within the Excel engine, which corrupts memory and permits alteration of the program’s execution flow. No explicit mention of remote exploitation is provided in the description, so the impact remains local to the machine that opens the malicious file.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Office Online Server. Specific version numbers are not disclosed, so all current releases of these products are potentially vulnerable until the Microsoft security update is applied.
Risk and Exploitability
The CVSS score of 7.8 reflects a high impact potential. An EPSS score of less than 1% indicates a very low probability of exploitation in the wild at present. The vulnerability is not listed in the CISA KEV catalog, which aligns with its low exploitation likelihood. Based on the description, it is inferred that the likely attack vector is the local opening of a malicious Excel document, as the description does not explicitly mention a remote interface. By opening such a document, an attacker can execute arbitrary code on the target user’s machine, posing a severe threat to confidentiality, integrity, and availability of that system.
OpenCVE Enrichment