Impact
Out-of-bounds write in Excel allows an attacker to execute arbitrary code on the victim’s machine, giving complete control over the system. This vulnerability is classified as CWE-787 and can compromise confidentiality, integrity, and availability of the affected environment.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. No affected version information is provided.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, and the EPSS score of <1% suggests a low probability of exploitation, but the vulnerability remains potentially dangerous. The vulnerability requires an attacker to supply a crafted Excel file that triggers a memory out-of-bounds write; the likely attack vector is local or remote via a malicious file that a user opens. The issue is not listed in CISA KEV, suggesting that large‑scale exploitation has not yet been observed.
OpenCVE Enrichment