Impact
An untrusted pointer dere allows an unauthorized attacker to execute code locally. The flaw is limited to the Excel component and can lead to full compromise of the system on which the file is opened.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Microsoft Office Online Server.
Risk and Exploitability
The CVSS v3.1 score of 7.8 indicates medium–high risk. The EPSS score of less than 1 % points to a low probability of active exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. The description does not explicitly state how the attacker achieves execution; based on the description, it is inferred that the vulnerability would be triggered when Excel processes an untrusted file, requiring the user to open or otherwise allow Excel to read a malicious workbook. If successful, the attacker privileges with the rights of the user opening the file.
OpenCVE Enrichment