Impact
A heap-based buffer overflow occurs in Microsoft Office Excel, permitting an unauthorized attacker to execute code locally. The flaw is identified as CWE-122 and enables the attacker to run arbitrary code on the system that opens the vulnerable workbook, potentially compromising data or escalating privileges. The attack demands that a malicious file be opened in Excel, meaning it is a local code‑execution vulnerability that can affect users with access to the system.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. The vulnerability applies to the specified versions across Windows, macOS, and x86 architecture as listed in the vendor documentation.
Risk and Exploitability
The CVSS score of 7.8 classifies this flaw as high severity. EPSS data is unavailable, and the issue is not listed in the CISA KEV catalog. The likely attack vector is local: an adversary crafts a malicious workbook and gets a user to open it, causing the buffer overflow and executing attacker code. No network or privileged escalation vector is indicated, so the threat largely impacts the endpoint and its users.
OpenCVE Enrichment