Microsoft Excel Remote Code Execution Vulnerability
CVE-2024-49028
7.8HIGH
Summary
A remote code execution vulnerability exists in Microsoft Excel that could enable an attacker to execute arbitrary code on a victim's machine when they open a specially crafted Excel file. This vulnerability poses significant risks, particularly in environments where Excel documents are frequently exchanged. Effective security measures and timely updates are essential to mitigate the threats associated with this vulnerability, ensuring that sensitive data and systems remain secure. For more details, refer to the vendor advisory.
Affected Version(s)
Microsoft 365 Apps for Enterprise 32-bit Systems 16.0.1
Microsoft Excel 2016 32-bit Systems 16.0.0.0 < 16.0.5474.1001
Microsoft Office 2019 32-bit Systems 19.0.0
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Collectors
NVD DatabaseMitre DatabaseMicrosoft Feed