Impact
An out-of-bounds read vulnerability exists in the xls_dumpSummary() function of libxls 1.6.3 OLE that parses a malicious .xls file to read memory beyond the intended buffer boundaries, which could expose unintended data or result in a program crash.
Affected Systems
Any application or service that incorporates libxls 1.6.3 to read or process .xls files is affected. This includes open‑source tools, custom scripts, and No specific vendors are listed, so consider all systems using this version as potentially at risk.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to supply a crafted .xls file to an application that uses libxls; no elevated privileges are needed. The accidental disclosure of memory contents but does not provide a privilege escalation path. The primary risk is information leakage or denial of service via application crash.
OpenCVE Enrichment