Impact
The vulnerability stems from Microsoft Office Excel using an uninitialized resource, which can allow an unauthorized local attacker to read data that it should not have access to. This flaw specifically leads to the disclosure of confidential information stored within a workbook or the system, compromising the confidentiality of the affected data. The weakness is classified as CWE‑908, indicating that an improper validation step leaves data in an unintended state.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024.
Risk and Exploitability
The CVSS score is 5.5, indicating moderate severity. The EPSS score is not available, so the likelihood of exploitation cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. The attack vector appears to be local, requiring an attacker with local access to trigger the uninitialized resource and gain the disclosed information. No remote code execution or privilege escalation mechanisms are described in the available data.
OpenCVE Enrichment