Impact
Microsoft Excel contains a flaw that allows an attacker with local access to expose sensitive system information. The vulnerability stems from an unintended exposure of data to an unauthorized control sphere. The primary impact is the disclosure of potentially confidential information that should remain internal to the system. Based on the description, it is inferred that no network or remote execution is required; the attacker must run a malicious Excel file or otherwise gain local execution capability.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise and multiple versions of Microsoft Office such as Office 2016, Office 2019, Office 2021, Office 2024, Office LTSC 2021, Office LTSC 2024, Office 365 for Mac, Office Mac 2021, and Office Mac 2024. The specific affected versions are not listed, so all installations of these editions are considered potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting limited current exploitation. The likely attack vector is local, requiring the attacker to run a malicious Excel instance or document. The risk is moderate but remains significant for environments that handle sensitive data within Office files.
OpenCVE Enrichment