Impact
An out‑of‑bounds read vulnerability in Microsoft Office Excel allows an unauthorized attacker to read memory beyond the bounds of an array, which can be leveraged to execute arbitrary code locally. The flaw is triggered when a malicious Excel file is opened, potentially giving the attacker full control over the affected system. This represents a significant compromise of both confidentiality and integrity for the end user. The weakness is identified as CWE‑125, which categorizes improper handling of buffer boundaries.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024 are all affected. No specific version numbers are listed in the CNA data, so any installation of the above products that has not received the vendor security update is potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity vulnerability; it is not listed in the CISA KEV catalog and the EPSS score is not available, suggesting that no widespread use of public exploits has been documented yet. Based on the description, the likely attack vector is an unauthorized user creating or delivering a malicious Excel workbook that, when opened on the victim’s machine, triggers the out‑of‑bounds read and enables local code execution. No explicit workaround is provided, so the attacker must rely on a privileged or local user to open the file.
OpenCVE Enrichment