Impact
A heap‑based buffer overflow in Microsoft Office Excel permits a local attacker with access to an affected system to execute arbitrary code on the device. The flaw arises when Excel processes data that exceeds the allocated memory buffer, allowing the attacker to control program flow and run malicious payloads. This flaw reflects a CWE‑122 heap‑based buffer overflow. Because the vulnerability grants code execution at the current user level, it can lead to full system compromise, data exfiltration, or the installation of persistent malware.
Affected Systems
The affected products are Microsoft 365 Apps for Enterprise, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. All listed editions of Windows and macOS Office are potentially vulnerable; administrators should verify that the latest security updates are installed on affected systems.
Risk and Exploitability
With a CVSS score of 7.8, the vulnerability is considered high severity. An EPSS score of < 1% indicates a very low, yet non‑zero, likelihood that this flaw will be actively exploited in the wild. The vulnerability is not listed in the CISA KEV catalog, indicating no known public exploits. Still, local code execution poses a serious threat in environments where users can open potentially malicious files. Prompt patching is therefore essential to mitigate even a low‑probability risk.
OpenCVE Enrichment