Impact
The vulnerability is caused by an uninitialized resource in Microsoft Office Excel, enabling a local attacker with execution privileges to read sensitive data that should remain confidential. This flaw represents an improper initialization weakness and is classified as CWE‑908. The impact is a breach of information confidentiality; no remote code execution or denial of service is possible.
Affected Systems
Affected Microsoft Office products include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. Any user running these versions may experience local disclosure of sensitive data.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. The EPSS score is not available, so the current exploitation probability cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local, requiring an attacker to execute code on the affected machine. Because local exploitation is required, the risk is limited to environments where an attacker can attain local execution privileges; nevertheless, the confidentiality compromise remains a significant concern.
OpenCVE Enrichment