Impact
A heap-based buffer overflow flaw (CWE-122) in Microsoft Excel allows an unauthorized attacker to execute code locally when a specially crafted workbook is opened. The overflow occurs during memory allocation for a workbook object, and as a result the attacker can run arbitrary code, potentially compromising the confidentiality, integrity, and availability of the affected machine.
Affected Systems
The vulnerability affects Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Office Online Server. No specific affected versions are disclosed; therefore any current releases of these products may be vulnerable until a fix is applied.
Risk and Exploitability
The CVSS score of 7.8 is considered high, indicating a substantial potential impact if the flaw is exploited. The EPSS score of < 1% indicates the likelihood of observed exploitation is very low at present, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack requires a victim to open a malicious workbook, making the vector local and contingent on user interaction; exploitation does not appear to be remotely exploitable without such interaction.
OpenCVE Enrichment