Impact
An out‑of‑bounds read flaw in Microsoft Office Excel permits an unauthorized attacker who can interact with an Excel process over a network to read memory contents that are not intended for exposure. The vulnerability, classified as CWE‑125, can be leveraged to disclose sensitive data, thereby violating confidentiality.
Affected Systems
The flaw affects multiple Microsoft Office products, including Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Office Online Server. Specific version details beyond the product names are not supplied in the advisory.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity vulnerability. EPSS is listed as less than 1 %, suggesting a low probability of exploitation at present, and the flaw is not in the CISA KEV catalog. Based on the description, the likely attack vector is a remote, network‑based interaction with the Excel application. An attacker could leverage the out‑of‑bounds read to gain unauthorized access to data located in process memory, potentially revealing sensitive information exchanged over the network.
OpenCVE Enrichment