Impact
The vulnerability is a heap‑based buffer overflow in Microsoft Excel that, when triggered by a crafted spreadsheet, allows an unauthorized local attacker to execute arbitrary code. The overflow is coupled with an integer overflow, enabling the attacker to corrupt heap objects and reshape execution flow. Local code execution permits full compromise of the affected user’s session, potentially affecting confidentiality, integrity and availability of the compromised machine.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024 are affected. Version ranges are not specified in the advisory.
Risk and Exploitability
The CVSS score of 7.8 indicates a moderate‑to‑high severity vulnerability. EPSS data is not available, and the flaw is not yet listed in the CISA KEV catalog, suggesting limited known exploitation but a possibility for future attacks. The likely attack vector is the local execution of a malicious Excel file or a phishing attachment. An attacker who successfully craft a spreadsheet file can trigger the heap overflow and obtain code‑execution privileges on the user’s machine, with no network‑based access required.
OpenCVE Enrichment