Impact
A heap-based buffer overflow exists within Microsoft Office Excel, allowing an attacker to execute arbitrary code locally. The vulnerability stems from improper boundary checks in memory management, categorized as CWE‑122. If an attacker gains a foothold in a session that can open a malicious workbook, they can trigger the overflow and run arbitrary code with the user’s privileges, potentially compromising the host system.
Affected Systems
Affected Microsoft products include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. No specific version numbers were supplied; the issue applies to all listed releases as of the CVE announcement.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, and the vulnerability is exploitable locally when a user opens a crafted Excel file. While the EPSS score is not available and the issue is not listed in CISA’s KEV catalog, the potential for local compromise makes it a significant risk for organizations. Exploitation requires the attacker to supply a malicious workbook to a target user, so social engineering or compromised sources are plausible attack vectors. Implementing mitigations promptly is advised to prevent local code execution.
OpenCVE Enrichment