Impact
A heap‑based buffer overflow in Microsoft Office Excel allows an unauthorized local attacker to execute arbitrary code in the context of the user. Once exploited, the attacker can run malicious payloads, potentially leading to data theft, further network movement, or other destructive actions. The vulnerability, identified as CWE‑122, is limited to local execution and does not provide remote control without additional compromise.
Affected Systems
The flaw affects multiple Microsoft Office products, including Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. Specific sub‑versions are not listed in the advisory, so all current releases of the mentioned products are potentially vulnerable until patched.
Risk and Exploitability
The CVSS score of 7.8 classifies the issue as high severity, while the EPSS score of less than 1% indicates a low yet non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The most probable exploitation scenario involves a malicious Excel file opened by a user; this inference is drawn from the nature of the heap overflow and the need for user interaction to trigger it. Because exploitation requires local access, an attacker must already have access to the target machine to inject payloads.
OpenCVE Enrichment