Impact
This vulnerability is a heap-based buffer overflow in Microsoft Office Excel that allows an attacker to execute arbitrary code locally on the host machine. The flaw arises when Excel processes a specially crafted workbook, causing a memory corruption that can be exploited to run user-supplied code. Because the attacker gains code execution on the target, sensitive data could be accessed, the system could be compromised, and further lateral movement or privilege escalation could be possible if higher privileges are available on the account that opened the file. The weakness is classified as CWE-122.
Affected Systems
Affected Microsoft products include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. No specific sub-version information is listed, so all currently supported releases of these products are potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates a high level of risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been documented yet. Likely attack vectors involve a malicious Excel file that an attacker supplies and that a user opens, which then triggers the heap overflow. Because the flaw requires local file access, the primary threat is from social engineering or compromised emails, but once opened, the attacker can run code with the privileges of the current user. The combination of a non-trivial CVSS score and the local execution nature makes this vulnerability a significant concern for organizations that rely on Microsoft Office to handle customer data.
OpenCVE Enrichment