Impact
A heap‑based buffer overflow exists in Microsoft Office Excel that allows an attacker who can supply a malicious file to execute code locally on the affected system. The flaw permits arbitrary code execution, which can compromise the confidentiality, integrity and availability of the user’s data and system. It is a classic unchecked memory write vulnerability mapped to CWE‑122, and the impact is limited to the privileges of the user running Excel.
Affected Systems
Affected are Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021 and Microsoft Office LTSC for Mac 2024. Versions are unspecified in the advisory.
Risk and Exploitability
The CVSS score of 7 indicates a moderate‑to‑high severity. No EPSS rating is available, but the lack of a KEV listing suggests the vulnerability is not known to be actively exploited in the wild yet. The likely attack vector is local – an attacker must get the victim to open a crafted spreadsheet or other Office document. Because execution occurs locally, users with administrative or elevated privileges are the most at risk. The risk remains significant enough that prompt patching is advised.
OpenCVE Enrichment