Impact
Stack‑based buffer overflow in Microsoft Excel (CWE‑121) permits an attacker to execute arbitrary code locally with the privileges of the user who opens a malicious workbook. The flaw originates from improper bounds checking when processing certain Excel input, allowing overflow of a stack buffer and the corruption of control flow. If successful, the attacker can run code that may compromise confidentiality, integrity, or availability on the affected machine.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Office Online Server. No specific build or patch level details are listed beyond the product families.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, while the EPSS score of less than 1% reflects a very low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the attacker must supply a malicious workbook that Excel processes, leading to local code execution when the user opens the file. Therefore, the attack requires the attacker to deliver the file to the target computer, confining the threat to environments where users can receive or open files. Currently, the risk is primarily local, but the impact of successful exploitation is substantial.
OpenCVE Enrichment