← back
CVE-2023-32029highCWE-125

Microsoft Excel Remote Code Execution Vulnerability

33Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.8epss 54%
exploitation probability
54%top 1% of all CVEs
observed exploitation
nono source reports it
In short

Microsoft Excel can execute malicious code when you open a specially crafted file, allowing an attacker to take control of your computer. This happens because Excel doesn't properly validate data before processing it.

Technical detail

Out-of-bounds read vulnerability in Microsoft Excel's parsing engine allows remote code execution through a maliciously crafted workbook file. An attacker can achieve code execution in the context of the user running Excel by exploiting improper memory bounds checking, requiring user interaction to open the malicious file.

Summary generated and translated by AI from the official description.
Microsoft Excel Remote Code Execution Vulnerability
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C