Impact
A flaw in Microsoft Office Excel caused by the use of an uninitialized resource permits a user to run arbitrary code with the privileges of the current user. Classified as CWE‑908, the vulnerability provides a local code execution path that could be abused to elevate privileges or exfiltrate data on the victim machine.
Affected Systems
The affected products include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Office Online Server. Because the specific version ranges are not provided, all current releases of these products are considered vulnerable until a vendor update is released.
Risk and Exploitability
The CVSS score of 7.8 rates this vulnerability as high severity, yet the EPSS score of less than 1% indicates a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local: a malicious or crafted Excel file must be opened by a user, or the attacker must have local access to deliver the file. There is no evidence of a remote exploitation path from the supplied data.
OpenCVE Enrichment