Impact
The vulnerability is a heap-based buffer overflow in Microsoft Office Excel that allows an unauthorized attacker to execute arbitrary code locally in the context of the user opening a malicious file. Classified as CWE-122, this memory corruption flaw can lead to local code execution with the privileges of the affected Office process.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Office Online Server. The scope covers all build versions of these products that have not received the latest Microsoft update, as specific build numbers were not disclosed in the advisory.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, while the EPSS score of less than 1% suggests a low but non‑zero chance of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, indicating no publicly known exploits yet. Based on the description, it is inferred that the attack requires the victim to open a malicious file, so the attack vector is local and may be carried out through shared drives or web portals that provide Office documents. The likely attack path involves an attacker delivering a maliciously crafted spreadsheet to a user; when the user opens the file, the heap-based buffer overflow can be triggered, allowing local code execution.
OpenCVE Enrichment