Impact
This heap-based buffer overflow flaw in Microsoft Office Excel permits an attacker to run arbitrary code on the target machine. By injecting malicious data into the application’s heap, the attacker can corrupt control data and gain program control. The consequence is a full compromise of the machine, allowing the attacker to read, modify, delete data, or install further malware.
Affected Systems
The vulnerability affects multiple Office product lines, including Microsoft 365 Apps for Enterprise, Office 2016, Office 2019, Office 2021, Office 2024, Office LTSC 2021, Office LTSC 2024, and Office for Mac releases of 2021 and 2024. The affected editions are both the standard and long‑term servicing channel versions on Windows and macOS.
Risk and Exploitability
The flaw carries a CVSS score of 7.8, indicating a high level of severity in terms of confidentiality, integrity, and availability. The EPSS score is not available, so the precise prevalence of exploitation is unknown, but the lack of a KEV listing does not diminish the risk presented by the flaw. Based on the description, it is inferred that an attacker would need to deliver a specially crafted Excel workbook or otherwise cause the target to open a malicious document; this could trigger the buffer overflow through remote or social‑engineering means. The conditions for exploitation appear to require the user to have privileges sufficient to run the application, though administrative rights are not necessary.
OpenCVE Enrichment