Impact
An out‑of‑bounds read vulnerability in Microsoft Office Excel allows an unauthorized local attacker to read memory contents outside the intended buffer, resulting in local disclosure of potentially sensitive data. The flaw is identified as CWE‑125 and can compromise confidentiality, but it does not enable code execution or broader system compromise.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024 are affected. No specific version ranges are listed in the CNA data, so all current releases within these product families may be impacted.
Risk and Exploitability
The CVSS base score of 5.5 reflects moderate severity, while an EPSS score of less than 1% indicates a low probability of exploitation in the wild. The vulnerability is not included in CISA’s KEV catalog. Based on the description, the attack vector is inferred to be local, requiring the attacker to have physical or trusted remote access to a machine running the affected Office installation. No remote exploitation has been documented, and the impact is limited to the disclosure of information residing in memory or files accessed by the user.
OpenCVE Enrichment