Impact
The vulnerability is a stack‑based buffer overflow in Microsoft Office Excel that permits an unauthorized attacker to execute code on the target machine. The official description indicates that this flaw is triggered when a crafted document is opened, enabling the attacker to run arbitrary code with the privileges of the user. The weakness is classified as CWE‑121, a stack‑based buffer overflow characterized by improper bounds checking.
Affected Systems
Microsoft products affected include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. The specific patch versions are not enumerated in the provided data, so organizations should refer to the Microsoft Security Response Center update guide for the latest applicable releases.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. The EPSS score is reported as less than 1%, suggesting a low probability of exploitation in the wild, but the vulnerability is still considered high because the flaw is triggered by a compromised file in the local environment. As the issue is not listed in CISA's KEV catalog, there are no publicly confirmed exploits at this time. The likely attack vector is an unauthorized user who opens a malicious Excel document; local execution of arbitrary code would occur with the privileges of the user.
OpenCVE Enrichment