Impact
A heap‑based buffer overflow in Microsoft Office Excel lets an unauthorized user run malicious code on the host system; it is inferred that opening or executing a compromised workbook triggers the overflow. The flaw can elevate the execution privileges to those of the signed‑in user, potentially granting full control if the user has administrative rights. The vulnerability is identified as CWE‑122 and is limited to local execution, but it can serve as a foothold for subsequent lateral movement or data exfiltration.
Affected Systems
The flaw affects Microsoft Office products listed by the CNA, including Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Office Online Server. Version details are not disclosed; administrators should consult the Microsoft update guide to confirm whether a given build contains the vulnerability.
Risk and Exploitability
The CVSS score of 7.8 marks it as high severity. With an EPSS score below 1% and no listing in CISA’s KEV catalog, the likelihood of widespread exploitation appears low, though the vulnerability remains exploitable locally. Based on the description, it is inferred that an attacker would need to supply a malicious spreadsheet that the user opens or runs on the target machine.
OpenCVE Enrichment