Impact
A double free flaw in Microsoft Office Excel can let an attacker run arbitrary code on the affected machine. The vulnerability is triggered when a specially crafted Excel file is opened, allowing the attacker to exploit the memory corruption and execute code with the privileges of the current user.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024 are all affected.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a malicious spreadsheet that an attacker delivers to a user, either via email or local file sharing. If an authorized user opens such a file, the double free can be exploited to execute code with the user's privileges. The impact is local code execution, but the scope can be significant if the user has elevated or administrative rights.
OpenCVE Enrichment