Impact
A stack‑based buffer overflow in Microsoft Office Excel permits an attacker who supplies a malicious workbook to execute arbitrary code with the privileges of the user who opens the file, potentially compromising the machine, exfiltrating data, or initiating lateral movement.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. All listed versions are vulnerable whenever the unpatched binaries are running, regardless of service or cumulative update status.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity with medium complexity. The vulnerability is local; an attacker must deliver the malformed workbook to the target machine and convince a user to open it. No EPSS score is published and the issue is not in the CISA KEV catalog, yet the local nature and the potential for widespread impact make prompt remediation critical.
OpenCVE Enrichment