Impact
Integer overflow or wraparound in Microsoft Office Excel permits an unauthorized attacker to execute code locally on the victim machine, potentially allowing the attacker to run arbitrary instructions with the privileges of the user. The weakness is a classic integer overflow (CWE-190) that can be triggered by crafting a malicious spreadsheet or file that exploits the overflow during processing.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity vulnerability with a considerable impact if exploited. The EPSS score is not available, so the explicit probability of exploitation is unknown. It is not listed in the CISA KEV catalog. Based on the description, the vulnerability requires local file access; an attacker would need to deliver a malicious Excel file to the target, implying a local or possibly phishing‑based delivery vector rather than a purely remote exploit.
OpenCVE Enrichment