Impact
This vulnerability is a heap‑based buffer overflow in Microsoft Office Excel that permits an attacker with local or otherwise unauthorized access to execute arbitrary code on the affected system. The flaw is classified as CWE‑122 and could allow the execution of payloads with the privileges of the user who opens a malicious workbook, potentially leading to full system compromise. The impact is limited to the compromised user’s session but can be escalated later if the attacker gains additional footholds.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. No specific version numbers are listed, implying all current releases remaining vulnerable until patched.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity and the EPSS score is less than 1%, suggesting a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation yet. An attacker would need to supply a malicious Excel file to the victim, so the potential attack vector is local or remote via social‑engineering or file‑sharing mechanisms. Given the high confidentiality, integrity, and availability impact, the risk remains high for organizations using unpatched Office deployments.
OpenCVE Enrichment