Impact
An out‑of‑bounds read flaw in Microsoft Excel allows an unauthorized attacker to read data that should be protected, resulting in the disclosure of local information. This vulnerability does not compromise system integrity or availability but can leak sensitive content stored on the victim’s machine.
Affected Systems
Microsoft Office products vulnerable to this flaw include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. These deficiencies affect both Windows and macOS builds within the listed product families.
Risk and Exploitability
The CVSS score of 5.5 classifies the vulnerability as medium severity and the EPSS score of < 1% indicates a low likelihood of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. Based on the description, the attack requires local access and privileged execution of a crafted Excel file; therefore, the likely attack vector is local. An attacker who can supply a malicious file or otherwise exploit Excel on the victim’s machine can read protected data until a patch is applied.
OpenCVE Enrichment