Impact
The vulnerability is a heap-based buffer overflow in the Microsoft Excel engine that permits an attacker to execute arbitrary code when a vulnerable workbook is opened. The flaw, identified as CWE‑122, can lead to full control over the local system in the context of the user who processes the malicious file. Because the code runs locally, the attack requires no additional system privileges beyond those of the victim.
Affected Systems
Affected are Microsoft Office products that use the vulnerable Excel component, including Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Office 2019, the long‑term servicing channel releases of Office 2021 and Office 2024, Office for Mac 2021 and 2024, and Office Online Server.
Risk and Exploitability
The CVSS score of 7.8 classifies the flaw as high severity, but the EPSS score of less than 1 % indicates a very low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation. The likely attack vector involves an attacker embedding malicious content in an Excel workbook that is then opened by a user, triggering the heap overflow and local code execution. No additional conditions are explicitly required beyond opening the crafted file.
OpenCVE Enrichment