Impact
A stack-based buffer overflow exists in Microsoft Office Excel. When a malicious workbook is opened, the overflow allows an attacker to execute arbitrary code on the victim’s machine. This flaw can compromise the confidentiality, integrity, and availability of the affected system, potentially giving the attacker full control over the computer. The description states the attacker can execute code locally, indicating that exploitation requires the victim to open the infected file, typically after obtaining it via email, web download, or other remote delivery channel.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. No specific version numbers were provided, so all current releases in these product families are potentially affected.
Risk and Exploitability
The CVSS score of 7.8 indicates a moderate to high severity for this issue. The EPSS score of less than 1% suggests that exploitation is unlikely at present, and the vulnerability is not listed in the CISA KEV catalog. The most probable attack vector is a user opening a crafted Excel file—this requires the user to be present on the local machine and to have permission to run the file. An attacker could distribute the malicious workbook via phishing or compromised websites to trigger the flaw.
OpenCVE Enrichment