Impact
An out-of-bounds read flaw in Microsoft Excel can allow an unauthorized local attacker to read sensitive data from memory. This issue, classified as CWE‑125, permits the disclosure of confidential information that may reside within. The description and impact information are limited to a local scenario; thus it does not enable remote compromise or escalation of privileges.
Affected Systems
Vendor Microsoft’s Office ecosystem is affected, including the 365 Apps for Enterprise, Excel 2016, Office 2019, Office 2021, Office 2024, Office for Mac 2021 and 2024, and Office Online Server. Specific product versions are not listed in the advisory, so users should assume all current releases of vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate severity, and the EPSS of less than 1% suggests a low probability of exploitation at present. Because the vulnerability requires local access and has not been reported in the CISA KEV catalog, the overall surface attack range remains limited. Nonetheless, the local disclosure can compromise sensitive data crafted Excel file, so remediation is advised.
OpenCVE Enrichment