Impact
An out‑of‑bounds read flaw in Microsoft Office Excel allows a local attacker to read arbitrary memory from the Excel process, leaking data that may be present in the target machine’s environment. The vulnerability is a textbook example of CWE‑125, where lack of bounds checking permits reading beyond a buffer’s limits. The immediate result is a confidentiality compromise; no integrity or availability effects are reported in the official description.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. All currently supported Office and Excel releases that Microsoft lists as affected are vulnerable.
Risk and Exploitability
The CVSS score of 5.5 indicates a medium severity flaw. EPSS data is not available and the vulnerability is not listed in CISA KEV, suggesting no known active exploitation. The likely attack vector is local; the attacker would need to have user access or another way to execute code on the target machine to trigger the read. Still, because the flaw lets an adversary read sensitive data, timely patching is recommended.
OpenCVE Enrichment