Impact
An out-of-bounds read in Microsoft Office Excel allows a local attacker to read memory contents from the running process. The flaw is classified as CWE-125, resulting solely in disclosure of sensitive data on the host powerfully accessed by the user, rather than causing denial of service or code execution.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, Office Online Server are all vulnerable. The specific version ranges are not provided in the data, but all listed editions exhibit the flaw.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity. The EPSS score of less than 1% suggests a low likelihood of exploitation at the time. The vulnerability is not in CISA’s KEV catalog, implying limited known exploitation. Likely attack conditions require unauthorized local access to the machine; no elevated privileges or remote exploitation are necessary.
OpenCVE Enrichment