Impact
The vulnerability is a heap‑based buffer overflow in Microsoft Office Excel that allows an unauthorized user to execute arbitrary code locally. This flaw corresponds to CWE‑122 and can result in full compromise of the system where the Office application runs, as an attacker could run code with the privileges of the current user.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Excel 2016, Office 2019, Office 2021 (LTSC), Office 2024 (LTSC), Office 365 for Mac, Office LTSC for Mac 2021, and Office LTSC for Mac 2024. The CVE references list does not specify exact patch levels or minor version numbers, so all current builds of the mentioned products are potentially vulnerable until a fix is applied.
Risk and Exploitability
The CVSS score of 7.8 denotes high severity, while the EPSS score is not available, leaving the current exploitation probability unclear but still significant. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is a malicious spreadsheet or document opened by the user; an unauthenticated attacker could deliver crafted content that triggers the overflow when Excel parses it. Successful exploitation requires the victim to open the crafted file.
OpenCVE Enrichment