Microsoft Excel Remote Code Execution Vulnerability
CVE-2024-49028

7.8HIGH

Key Information:

Summary

A remote code execution vulnerability exists in Microsoft Excel that could enable an attacker to execute arbitrary code on a victim's machine when they open a specially crafted Excel file. This vulnerability poses significant risks, particularly in environments where Excel documents are frequently exchanged. Effective security measures and timely updates are essential to mitigate the threats associated with this vulnerability, ensuring that sensitive data and systems remain secure. For more details, refer to the vendor advisory.

Affected Version(s)

Microsoft 365 Apps for Enterprise 32-bit Systems 16.0.1

Microsoft Excel 2016 32-bit Systems 16.0.0.0 < 16.0.5474.1001

Microsoft Office 2019 32-bit Systems 19.0.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

Collectors

NVD DatabaseMitre DatabaseMicrosoft Feed
.