Impact
Microsoft Office Excel contains a buffer over-read vulnerability that can be exploited locally by an unauthorized attacker to read data beyond the bounds of a buffer. The flaw allows disclosure of sensitive information from memory, thereby compromising confidentiality. The weakness is classed as CWE-126, which involves improper handling of buffer boundaries.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. No specific affected version ranges are listed in the data.
Risk and Exploitability
The vulnerability is rated with a CVSS score of 5.5, indicating a moderate risk. An EPSS score is not provided, and the flaw is not listed in the CISA KEV catalog. Attackers must be local or have sufficient desktop access to trigger the buffer over-read. The flaw is not exploitable remotely and requires that the attacker be able to open or otherwise interact with the vulnerable Excel or related Office application.
OpenCVE Enrichment