Impact
The vulnerability is a type confusion flaw in Microsoft Excel that permits an attacker to execute arbitrary code locally when a specially crafted workbook is opened. This flaw enables code execution with the privileges of the current user, compromising confidentiality, integrity, and availability of the affected system. The weakness is identified as CWE‑843, reflecting a mismatch between expected and actual data types.
Affected Systems
Affected products belong to Microsoft Office suite across several release streams. Relevant versions include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. No specific version numbers are listed, so all current releases of these products are potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.8 classifies this flaw as High severity, while no EPSS score is available and it is not listed in the CISA KEV catalog. Without an available exploit probability metric, the threat remains significant due to the nature of local code execution. The attack vector is inferred to be via a malicious workbook that a user must open, indicating that user education and cautious handling of files remain critical.
OpenCVE Enrichment