Impact
A heap‑based buffer overflow flaw exists in Microsoft Office Excel that can be triggered by an unauthorized attacker to execute arbitrary code locally on the affected machine. The vulnerability resides in the way Excel processes certain Excel files, allowing a crafted payload to overwrite memory and gain control of the execution flow. This flaw satisfies CWE‑122 and can lead to loss of confidentiality, integrity, and availability by allowing the attacker to run any code with the privileges of the logged‑in user.
Affected Systems
The flaw affects a broad range of Microsoft Office products, including Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024.
Risk and Exploitability
With a CVSS score of 7.8 the vulnerability is scored as high severity. The EPSS score is 0.00332 (<1%) and the CVE is not listed in CISA’s KEV catalog, indicating no confirmed widespread exploitation yet. The likely attack vector requires an attacker to supply or entice a user to open a malicious Excel file, after which the buffer overflow can be triggered to execute code locally. Given the local execution requirement, the impact is limited to the affected user or system, but the severity of the flaw and the absence of mitigation make it a notable risk.
OpenCVE Enrichment