Impact
Microsoft Office Excel contains a heap‑based buffer overflow that allows an attacker to execute arbitrary code when the vulnerable application processes a specially crafted file. The flaw can lead to execution of attacker code with the privileges of the user running Excel, potentially compromising confidentiality, integrity, and availability of the affected system. The description refers to local execution, but the official title and known risk model suggest the flaw can be leveraged remotely by delivering a malicious spreadsheet to a user.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016 and Microsoft Office 2016, Office 2019, Office 365 for Mac, Office LTSC 2021 and LTSC 2024, and their Mac OS equivalents. Specific version ranges are not listed in the available data.
Risk and Exploitability
The CVSS score is 7.8, indicating high severity, while the EPSS score is unknown and the vulnerability is not listed in CISA’s KEV catalog. The likely attack path involves providing a malicious Excel workbook to a user, either via email, a network share, or another file distribution mechanism. Availability of a remediation update mitigates the risk, but until it is installed, the vulnerability remains exploitable under conditions that allow the attacker to supply the crafted file.
OpenCVE Enrichment