Impact
An out‑of‑bounds read bug in Microsoft Office Excel allows an attacker to read data from memory locations beyond the intended buffer, potentially exposing sensitive information. The vulnerability is local and does not grant elevated privileges. The disclosure is limited to the data stored in memory at the execution time of the read operation.
Affected Systems
The flaw affects Microsoft Office products including Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Office Online Server. Any installation of these products that has not applied the vendor’s update is vulnerable.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate impact. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the attack requires local access to the machine and a user running an affected Office process, the risk is confined to users who can execute the application. Without a local presence, the vulnerability cannot be exploited remotely.
OpenCVE Enrichment