Impact
A heap-based buffer overflow in Microsoft Office Excel enables an unauthorized attacker to execute arbitrary code locally on a vulnerable system. The flaw does not rely on external network connections and can be triggered by opening a specially crafted Excel file, allowing the attacker to gain code execution rights at the user’s privilege level.
Affected Systems
The vulnerability affects multiple Microsoft Office product lines including Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. Specific version information is not supplied, so any install of these products is potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates a high risk to affected systems. While the EPSS score is listed as <1%, the absence from the CISA KEV catalog implies no known active exploitation. The flaw is local; the likely attack vector is an attacker delivering a specially crafted Excel file to a user, who must open or otherwise provide the file to the vulnerable Office installation. Based on the description, this triggers a heap-based buffer overflow (CWE‑122). Once executed, an attacker can run arbitrary code with the privileges of the Windows user, potentially allowing privilege escalation or further compromise of the system.
OpenCVE Enrichment