Impact
The vulnerability is an out-of-bounds read (CWE‑125) in Microsoft Office Excel that allows an attacker to execute arbitrary code on the host when a malicious workbook is opened. This local code execution could compromise the confidentiality, integrity, or availability of the system.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Office Online Server. The advisory does not provide specific version numbers.
Risk and Exploitability
The CVSS score of 7.8 classifies the vulnerability as high severity, but the EPSS score of less than 1 percent indicates a low probability of current exploitation. The flaw is not listed in CISA’s KEV catalog. Exploitation requires a victim to open a malicious workbook, so the attack vector is inferred to be phishing or user interaction. Successful exploitation grants an attacker full control over the victim’s workstation.
OpenCVE Enrichment