Microsoft Excel
cpe:2.3:a:microsoft:excel:*:*:*:*:*:*:*
A remote code execution vulnerability has been identified in Microsoft Excel. This issue allows an attacker to execute arbitrary code on the affected system. The vulnerability is present in multiple versions of Microsoft Office, including the 2021 and 2019 LTSC releases, as well as in Microsoft 365 Apps for Enterprise. The root cause of the vulnerability is an untrusted pointer dereference, which can be exploited by manipulating how Excel handles certain types of data.
Exploitation of this vulnerability could lead to remote code execution on the affected system.
Users can apply the security update available through the Microsoft Update Catalog or via the Click-to-Run service, depending on their version of Microsoft Office. Specific update instructions can be found in the release notes for each affected product.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.