Impact
A heap-based buffer overflow in Microsoft Office Excel allows an attacker to execute arbitrary code locally on the host. This flaw, classified as CWE-122, can compromise confidentiality, integrity, and availability if a malicious workbook is opened or otherwise the vulnerable instance of Excel is interacted with. The impact is the ability for an attacker to run code with the privileges of the user.
Affected Systems
The vulnerability affects Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. No specific patch versions are listed, so all editions of the aforementioned products are potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, which does not diminish the seriousness of the flaw. Based on the description, the likely attack vector is an attacker delivering a malicious Excel workbook that the user opens or otherwise interacts with; the vector is inferred because the official advisory does not explicitly state it. Because the flaw allows local code execution, an attacker can potentially compromise the entire system if they gain access to a user’s session. The absence of EPSS or KEV data makes it difficult to gauge current exploitation activity, but given the high severity, the risk remains significant.
OpenCVE Enrichment