Impact
Microsoft Office Excel suffers an out‑of‑bounds read that allows an unauthorized attacker to achieve remote code execution over a network. The flaw allows the attacker to read beyond the intended buffer and influence program control, violating confidentiality, integrity, and availability of the affected system.
Affected Systems
The vulnerability affects several Microsoft Office products, including Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. No specific version ranges are listed.
Risk and Exploitability
With a CVSS score of 8.8, the issue is considered high severity. The EPSS score is <1% and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is remote over a network; an attacker who can deliver a crafted Excel file to the target system can trigger the out‑of‑bounds read and execute arbitrary code.
OpenCVE Enrichment