Impact
A heap‑based buffer overflow is present in Microsoft Office Excel that enables an attacker to run arbitrary code with the privileges of the user who opens a malicious workbook. The vulnerability is triggered when Excel parses specially crafted spreadsheet data and can grant the attacker complete control over the affected system, including execution of malware, persistence, or data theft.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024 are affected. The flaw exists in all supported platforms, both Windows and macOS.
Risk and Exploitability
The CVSS score of 7.8 indicates a high potential for local code execution with no-browser isolation. EPSS data is not available and the vulnerability is not yet listed in the CISA KEV catalog, implying no known active exploitation at this time. The attack vector is inferred; an adversary would need to supply a malicious Excel file, likely via email, a web download, or a shared network location, and the victim must manually open or preview the file for the exploit to execute.
OpenCVE Enrichment