Impact
A stack-based buffer overflow in Microsoft Office Excel enables an attacker to execute arbitrary code locally. The flaw results from improper bounds checking when processing certain inputs, classified as CWE‑121 and CWE‑20. Successful exploitation would allow execution under the privileges of the user who opens the affected file, potentially leading to system compromise.
Affected Systems
The affected products include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Microsoft Office Online Server. The issue does not enumerate specific build numbers, so all current releases of these product lines may be vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity vulnerability. The EPSS score of less than 1% suggests a low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. It is inferred that the attack vector is local; an attacker must provide a malicious file that a user opens. The flaw does not provide a remote exploitation route. Once the file is opened, the attacker can run arbitrary code with the user's privileges, potentially escalating privileges or enabling further attacks.
OpenCVE Enrichment