Impact
An untrusted pointer dereference vulnerability in Microsoft Office Excel can be exploited by an attacker who has local execution privileges to read sensitive information from memory or the underlying system. The flaw allows local disclosure of confidential data, potentially compromising user privacy but not enabling remote code execution. The weakness is a classic untrusted content leading to information leakage, as identified by CWE‑822.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Microsoft Office Online Server. The CVE does not specify narrowed version ranges, so all currently supported releases within these product families are potentially impacted.
Risk and Exploitability
The CVSS base score of 5.5 indicates moderate risk, while an EPSS score of less than 1% suggests a low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require a local attacker to provide malicious content that triggers the untrusted pointer dereference; it does not allow network attackers to exploit the system remotely.
OpenCVE Enrichment