Impact
A type confusion flaw in Microsoft Excel lets an unauthenticated local attacker access data stored in a workbook. The vulnerability arises from improper handling of incompatible resource types, allowing the attacker to read local information that should remain private. Accordingly, the primary impact is the disclosure of potentially sensitive data with no direct influence on system integrity or availability.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Office Online Server. All versions listed under these product lines are vulnerable unless a patch is applied.
Risk and Exploitability
The CVSS assessment gives a 5.5 score, indicating moderate severity. No EPSS score is available, so the likelihood of exploitation in the wild cannot be quantified from the data. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local, requiring an attacker to have access to a user’s machine to trigger the type confusion and read the workbook contents.
OpenCVE Enrichment