Microsoft Excel Remote Code Execution Vulnerability

Vulnerability

A remote code execution vulnerability has been identified in Microsoft Excel. This issue allows an attacker to execute arbitrary code on the affected system. The vulnerability is present in multiple versions of Microsoft Office, including the 2021 and 2019 LTSC releases, as well as in Microsoft 365 Apps for Enterprise. The root cause of the vulnerability is an untrusted pointer dereference, which can be exploited by manipulating how Excel handles certain types of data.

Impact

Exploitation of this vulnerability could lead to remote code execution on the affected system.

Remediation

Users can apply the security update available through the Microsoft Update Catalog or via the Click-to-Run service, depending on their version of Microsoft Office. Specific update instructions can be found in the release notes for each affected product.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
10.0
exploitability
4.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.