Impact
The vulnerability stems from a type‑confusion flaw that lets an attacker access a resource with an incompatible type, enabling them to execute arbitrary code over a network within Microsoft Excel. This weakness grants the attacker full control over the affected system, compromising confidentiality, integrity, and availability. The flaw is identified as CWE‑843.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024.
Risk and Exploitability
With a CVSS score of 8.8, the risk is high. The EPSS score is not available, so the current exploitation probability is unknown, but the lack of a KEV listing suggests no public exploit is confirmed yet. The likely attack vector is network‑based, requiring the attacker to deliver malicious content to a vulnerable Excel instance.
OpenCVE Enrichment