Impact
This vulnerability is a stack-based buffer overflow known as CWE-121. It is present in several Microsoft Office Excel releases and enables an attacker who delivers a specially crafted Excel file to a user to execute arbitrary code within the context of that user. The primary consequence is that the attacker can gain complete control of the host system on which the file is opened.
Affected Systems
Affected are a range of Microsoft Office suites, including Microsoft 365 Apps for Enterprise, Excel 2016, Office 2016, Office 2019, Office 365 for Mac, Office LTSC 2021, Office LTSC 2024, Office LTSC for Mac 2021 and Office LTSC for Mac 2024. No specific version numbers are provided in the data, so any build of these products may be vulnerable until patched.
Risk and Exploitability
The CVSS score is 7.8, indicating a high severity. EPSS data is not available, so the exact exploitation likelihood is uncertain, though the vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is remote or local delivery of a malicious Excel workbook that causes the overflow when opened; the vulnerability provides local code execution on the user’s machine.
OpenCVE Enrichment