Impact
An out‑of‑bounds read flaw in Microsoft Office Excel permits a local, unauthorized attacker to read sensitive data from memory, revealing information that should be private. This attack leverages a boundary check failure, classified as CWE‑125, and can expose confidential data without escalating privileges or executing code. The vulnerability does not allow remote execution or denial of service, but it does represent a moderate risk of data leakage to users with local access.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. Specific version ranges are not disclosed, so any installations matching these product lines may be impacted.
Risk and Exploitability
The CVSS score of 5.5 indicates a medium severity. The EPSS value being less than 1% signifies a very low probability of exploitation currently observed. The vulnerability is not listed in the CISA KEV catalog. Attackers would need local access to a system running an affected version of Excel; remote exploitation is unlikely based on the disclosed details.
OpenCVE Enrichment