Impact
A heap-based buffer overflow in Microsoft Office Excel allows an attacker who supplies a malicious spreadsheet to execute arbitrary code locally on the victim’s machine. The flaw arises in the handling of crafted Excel files, enabling code execution with the privileges of the user who opens the document. This vulnerability is classified as CWE‑122.
Affected Systems
Microsoft Office products including Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Office Online Server are impacted. All versions listed in the known vendor and product list are vulnerable until patched.
Risk and Exploitability
The CVSS score of 7.8 classifies the vulnerability as moderate to high, while the EPSS score of < 1 % indicates a low probability of exploitation in production environments. It is not listed in the CISA KEV catalog. The description implies that exploitation requires an attacker to provide or open a malicious Excel document on the target system; no remote execution path is documented. Therefore locally.
OpenCVE Enrichment