Impact
An out‑of‑bounds read flaw in Microsoft Excel allows an unauthorized local attacker to read sensitive data from memory while the application is running. This can expose confidential information stored in the victim’s Excel session, leading to a breach of the confidentiality boundary. The weakness is identified as CWE‑125, which denotes improper handling of buffer bounds.
Affected Systems
The vulnerability affects Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Office 2016, Office 2019, Office 365 for Mac, Office LTSC 2021, Office LTSC 2024, Office LTSC for Mac 2021, and Office LTSC for Mac 2024. No specific version numbers are listed, so any installation of these products that has not received the forthcoming patch is considered vulnerable.
Risk and Exploitability
The CVSS score of 5.5 places the vulnerability in the medium severity range, and there is no EPSS score available, indicating a lack of publicly known exploitation data. The flaw is local; an attacker would need to convince a user to open a malicious workbook or use local access to trigger the out‑of‑bounds read. Because it is not listed in CISA’s KEV catalog, there is no evidence of active exploitation in the wild, but the local nature of the attack and the ability to read arbitrary memory still pose a moderate risk to affected users.
OpenCVE Enrichment