Impact
This vulnerability is an out‑of‑bounds read flaw in Microsoft Excel. It allows any user who can open a specially crafted spreadsheet to read memory beyond buffer boundaries, which can be leveraged to trigger local code execution on the victim system. The flaw maps to CWE‑125 (Out‑of‑Bounds Read). Because the attack requires only that the victim execute a malicious Excel file, confidentiality, integrity, and availability of the machine can be compromised without additional access.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, and the corresponding Mac versions for LTSC 2021 and 2024. No specific affected version information is provided. All of these versions are listed as vulnerable in the Microsoft update guide.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, while the EPSS score of less than 1% indicates a low probability of widespread exploitation at present. The vulnerability is not listed in CISA's KEV catalog. The likely attack vector is the execution of a crafted spreadsheet file by an unauthorized user on a local system. An attacker needs only file‑level access; no network interaction or elevated privileges are required, making local attack surfaces valuable.
OpenCVE Enrichment