Impact
A use-after-free flaw (CWE-416) in Microsoft Office Excel allows an unauthorized attacker to execute arbitrary code locally. The vulnerability is a memory corruption issue that causes Excel to read from freed memory, which can be leveraged to run arbitrary code with the privileges of the user who opens the file.
Affected Systems
The affected products are Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Office Online Server. No specific version information is supplied for these products.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity impact. The EPSS score of less than 1% suggests exploitation is currently unlikely and there are no public incidents. The vulnerability is not listed in CISA’s KEV catalog, so mass exploitation has not been observed. The likely attack vector is local; an attacker would need to entice a user to open a malicious file or otherwise gain local access to drive the file open. The use‑after‑free condition means the code runs with the privileges of the account that opens the file.
OpenCVE Enrichment