Impact
The vulnerability is an out‑of‑bounds read in Microsoft Excel that allows a local attacker to read memory locations beyond the intended bounds, potentially exposing confidential data stored inside the Excel process or the operating system. The flaw is classified as CWE‑125, indicating a read past the end of a buffer that can reveal sensitive information without requiring elevated privileges.
Affected Systems
Affected are Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. The exact impacted build numbers are not listed, but any product matching the vendor and product names above is potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.5 denotes a moderate severity, and the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. Because it requires local access to the affected Office installation, the attack vector is likely local, and no publicly available remote exploitation tools are documented.
OpenCVE Enrichment