Impact
The vulnerability is a type‑confusion flaw that occurs when Excel accesses a resource using an incompatible type (CWE-843). The bug allows local code execution, letting a user who opens a malicious file run arbitrary code with the privileges of that user. This flaw stems from how Excel parses certain data types during file handling, leading to a cascade of unchecked memory operations. The resulting impact is that a malicious Office file can compromise the host system, potentially allowing the attacker to install malware, exfiltrate data, or elevate privileges when combined with other escalations.
Affected Systems
Affected Microsoft products include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 2021 Long‑Term Servicing Channel, Microsoft Office 2024 Long‑Term Servicing Channel, Microsoft Office 365 for Mac, Microsoft Office 2021 for Mac, and Microsoft Office 2024 for Mac. All current releases of these products are impacted until a patch is applied.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, yet the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local: a user must open or run an Excel file crafted to exploit the type‑confusion bug. Remote exploitation over a network is not supported by the current description. Because any authenticated user can trigger the flaw, the risk to individual systems is significant, especially in environments where Excel files are regularly shared or imported.
OpenCVE Enrichment