Impact
Improper input validation in Microsoft Excel enables an attacker who can locally craft a malicious file to read data that should be protected on the user’s machine. The vulnerability does not allow remote execution, privilege escalation, or persistence; it simply allows the attacker to extract sensitive information from the local environment, which may include other Office documents, system configurations, or environment variables.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, Microsoft Word 2016.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, while an EPSS of less than 1% shows a very low probability of exploitation at the time of analysis. The vulnerability is not listed in CISA’s KEV catalog, suggesting no documented high‑profile attacks. Because the exploit requires the attacker to supply a crafted workbook to a local user or process, the attack vector is local; it is not susceptible to remote attacks unless an internal attacker is present or a user voluntarily opens a malicious file.
OpenCVE Enrichment