Impact
A use‑after‑free vulnerability in Microsoft Office Excel allows an attacker to cause the application to execute arbitrary code on the system where a malicious workbook is opened. The flaw resides in the handling of freed memory after certain operations, enabling code that runs with the privileges of the user who opens the file. This can lead to complete compromise of the victim’s machine.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. Detailed version information is not provided by the CNA; all listed instances of the above products are potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, while no EPSS score is available, making it unclear how frequently attackers are attempting exploitation. The vulnerability is not listed in the CISA KEV catalog. Likely exploitation requires an attacker to deliver a crafted Excel file, often via email, web download, or social engineering, and the victim must open the file for the code to run. Once executed, the attacker can gain full control of the affected system.
OpenCVE Enrichment