Impact
Microsoft Office Excel contains a stack-based buffer overflow that enables an attacker to execute arbitrary code locally. The flaw arises from improper handling of spreadsheet data on the stack, leading to overwriting return addresses and hijacking control flow. Based on the description, it is inferred that the exploit would involve feeding a specially crafted Excel workbook to the vulnerable function, which then allows execution of code with the privileges of the user opening the file. The vulnerability is classified under CWE-121 and CWE-193.
Affected Systems
The flaw impacts Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. Specific affected version ranges are not provided in the data.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, meaning the vulnerability can be used to cause significant damage if exploited. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no documented widespread exploitation at present. Based on the description, it is inferred that the attack would require an attacker to supply a crafted Excel file and convince a user to open it locally. Once the workbook is processed, the stack corruption leads to code execution, making the risk contingent on user interaction and local file handling. The likely attack vector is local, requiring user action, though enterprise controls such as Protected View may mitigate exploitation.
OpenCVE Enrichment