Impact
The vulnerability allows an attacker that has local access to trigger the disclosure of sensitive system information from Microsoft Excel. The flaw is an improper release of information (CWE‑497) that can lead to the leakage of data that should otherwise be protected. The exposure can compromise confidentiality by revealing configuration details or other secrets that the application handles.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. The affected versions are unspecified but include the above editions as listed by the CNA.
Risk and Exploitability
The CVSS base score of 5.5 indicates moderate severity. No EPSS score is available, so the exact exploitation probability is unknown, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local, meaning that an attacker must gain some form of local access to the system to exploit the flaw and read the disclosed information.
OpenCVE Enrichment