Impact
Out-of-bounds read in Microsoft Office Excel enables a local attacker to read memory and disclose data that is not intended to be exposed. The flaw is classed as CWE‑125 and CWE‑20 and permits unauthorized disclosure of confidential information when an Excel file is opened by an account with local privileges.
Affected Systems
The vulnerability affects Microsoft Office 2016, Office 2019, Office 365 for Mac, Office LTSC 2021, Office LTSC 2024, Office Mac 2021, Office Mac 2024, and Microsoft 365 Apps for Enterprise across supported platforms. No specific version ranges are listed; all listed Office products are potentially affected.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, and the EPSS score is unknown, so the likelihood of exploitation is uncertain. The vulnerability is not listed in the CISA KEV catalog. Attack requires local file access and the ability to open a malicious Excel document, so exploitation would typically require user interaction or a local foothold, making it less tenable than remote exploits.
OpenCVE Enrichment