Impact
The flaw is an out‑of‑bounds read that allows an attacker to execute arbitrary code on a user’s machine by sending a specially crafted Excel file. Once the malicious workbook is opened, the attacker can run code without needing elevated privileges. This represents a classic local code execution vulnerability.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. No specific version ranges were identified, so all releases of these components are potentially vulnerable until the vendor issues a fix.
Risk and Exploitability
The CVSS base score of 7.8 signals high severity, and the flaw can be triggered remotely by supplying a malicious workbook. Although an EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, the lack of a mitigation does not reduce the risk. The most probable attack vector is an attacker delivering the malicious file via email, download, or network share, where a user opens it and the exploit activates.
OpenCVE Enrichment