Impact
The vulnerability is a heap-based buffer overflow (CWE-122) in Microsoft Office Excel that allows an unauthorized attacker to execute arbitrary code locally. When a user opens a crafted Excel file, the buffer overflow can be triggered and code runs with the privileges of the current user. This flaw enables attackers to take control of the affected system if the user opens a malicious file.
Affected Systems
Microsoft products affected include Microsoft 365 Apps for Enterprise, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. Specific version information is not provided in the advisory.
Risk and Exploitability
The CVSS score of 7.8 indicates a high impact with the possibility of arbitrary code execution. The EPSS score of less than 1% suggests that the likelihood of exploitation is currently very low, and the vulnerability is not listed in CISA’s KEV catalog. The primary attack vector is likely exploitation through a malicious Excel file that must be opened by the victim; unauthorized remote exploitation without user interaction is not indicated.
OpenCVE Enrichment