Impact
An out‑of‑bounds read flaw in Microsoft Office Excel allows an attacker who can reach the application over a network to read memory that should not be accessible, exposing confidential information. The vulnerability maps to CWE‑125, which signifies an improper handling of memory bounds. The impact is primarily the unauthorized disclosure of data, damaging confidentiality, and potentially allowing the attacker to gain additional insight into the system.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024 are affected. No specific version ranges are provided beyond the product names.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS of less than 1% shows a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Likely exploitation requires the attacker to have network access to the vulnerable Office process; once a connection is established, the attacker can trigger the out‑of‑bounds read and obtain memory contents. The threat is limited to disclosure and the risk of further compromise depends on the sensitivity of the data accessed.
OpenCVE Enrichment