Impact
A numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally on a victim’s machine. The flaw originates from improper handling of numeric data, causing truncation that can alter how the program processes the input. This constitutes a local code execution vulnerability. The weakness is classified under CWE‑197, Numeric Truncation Error. The CVE documentation does not describe additional weaknesses such as buffer overflow.
Affected Systems
Affected systems include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. Any user running these products without the latest security update is susceptible.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity while the EPSS score of less than 1% implies a very low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalogue. Likely attack vectors require the victim to open a specially crafted spreadsheet, which may be delivered via file‑delivery or social engineering. Despite the low exploitation likelihood, the potential for local code execution warrants prompt remediation.
OpenCVE Enrichment