Impact
An out-of-bounds read bug in Microsoft Office Excel permits an attacker to read memory data that should be protected and send that information over a network, potentially exposing sensitive data. The vulnerability is located in a component that processes spreadsheet data and is identified by CWE-125, indicating an out-of-bounds read condition. The official description confirms that the flaw allows an unauthorized attacker to disclose information when a malicious file is opened or accessed.
Affected Systems
The affected products include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. These are all versions of Microsoft's Office suite spanning desktop and Mac platforms.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, and the EPSS score of less than 1% suggests a low rate of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is that an attacker crafts a malicious Excel file that triggers the out-of-bounds read; when a user opens the file, the application reads beyond intended memory bounds and sends the captured data over the network. No specific authentication or privilege escalation is required, and the impact is limited to information disclosure rather than code execution or denial of service.
OpenCVE Enrichment