Impact
A buffer over‑read in Microsoft Office Excel enables an unauthorized attacker to read memory beyond intended bounds. The vulnerability can expose sensitive data, such as credentials or confidential file content, when triggered by a crafted Excel file or object.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024 are affected. No specific version constraints are provided, so all releases of these products may be vulnerable.
Risk and Exploitability
The CVSS score of 6.5 classifies the issue as a moderate severity information disclosure. The EPSS score is not available, preventing assessment of current exploitation likelihood, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the most likely attack vector is through the network, where an attacker delivers a malicious Excel file to a user or system that can interpret it, potentially allowing the over‑read to leak memory contents.
OpenCVE Enrichment