Impact
The vulnerability is an untrusted pointer dereference in Microsoft Office Excel that allows an attacker with control over a local file or a local execution environment to run arbitrary code within the user’s context. This flaw is classified as CWE‑822, which indicates unsafe handling of pointers that can lead to memory corruption. An exploited instance could give the attacker full access to the system’s resources, enabling data theft, modification, or deletion, and potentially allowing lateral movement within the network.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. Version specifics are not enumerated in the CVE entry, so all current releases within these product families are potentially vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score is 7.8, indicating high severity, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Attackers would need to deliver a crafted Excel file or otherwise gain local execution privileges to trigger the flaw, making it a local code‑execution vulnerability. Because the exploit requires local access, the risk is higher for systems that automatically open or execute files from untrusted sources, and the lack of a KEV listing suggests no widespread active exploitation has been reported at this time, but the high CVSS score warrants prompt remediation.
OpenCVE Enrichment