Impact
A heap-based buffer overflow in Microsoft Office Excel can be triggered by an attacker who furnishes a specially crafted workbook, allowing that attacker to execute code with the privileges of the user who opens the file. The vulnerability is classified as CWE‑122, indicating improper bounds checking around dynamic memory, which leads to arbitrary code execution on the victim’s machine. If exploited, the attacker gains full control of the local system and can further propagate within the environment.
Affected Systems
Microsoft Office products, including Microsoft 365 Apps for Enterprise, Excel 2016, Office 2019, Office 2021, Office 2024, Office 365 for Mac, and the corresponding Long Term Servicing Channel releases for Mac, are all susceptible. No specific version range was disclosed, suggesting that recent or current releases of these products are affected.
Risk and Exploitability
The CVSS score of 7.8 indicates a high risk of impact, but an EPSS score is not available, so the likelihood of exploitation in the wild cannot be quantified. The flaw is not listed in the CISA KEV catalog, and publicly known exploitation or proof‑of‑concept code has not been reported. The typical attack vector requires an authorized user to open a malicious file, making it a local code‑execution scenario rather than a remote attack.
OpenCVE Enrichment