Impact
An out-of-bounds read flaw in Microsoft Office Excel permits an unauthorized user to execute code on the local system. The vulnerability originates from improper bounds checking when processing Excel files, which can lead to arbitrary code execution if the file is opened or processed by a user who has ability to place the file in a location that will be read by the software. The impact is the loss of confidentiality, integrity and availability of the affected system, as malware could run with the privileges of the logged‑in user. The weak point is classified under CWE-125, an out-of-bounds read.
Affected Systems
The flaw affects multiple Microsoft Office product families including Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Office Online Server. All versions listed in the CNA product list are susceptible.
Risk and Exploitability
The CVSS score of 7.8 indicates a high level of severity. EPSS is not available, so the likelihood of exploitation cannot be quantified from the current data. The vulnerability is not listed in the CISA KEV catalog. Because the problem requires the victim to open a malicious file locally, the attack vector is inferred to be local and relies on user interaction or the presence of a file in a directory accessed by the application. A bypass of the normal bounds verification would allow execution of arbitrary local code with the privileges of the user.
OpenCVE Enrichment