Skip to content
Auto-CTI
Back to today
NEW CRITICAL A3

Microsoft Excel (2016), Office (2019, 2021 and 2024) and 365 Apps: Vulnerability Enables Code Execution

A BSI Warn- und Informationsdienst (WID): Schwachstellen-Informationen (Bürger Cert) ·

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key insight

BSI warns of critical code execution vulnerability in multiple Microsoft Office versions triggered by Use-After-Free, requiring immediate patches.

Description

A Use-After-Free vulnerability in Microsoft Excel 2016, Office 2019, 2021, 2024, and 365 Apps allows a remote, anonymous attacker to execute arbitrary code with the privileges of the logged-in user. The vulnerability can be triggered by opening a specially crafted Office file. Affected versions are widely deployed in enterprise environments. BSI classifies the vulnerability as critical and recommends immediate patching.

Risk score

37
cvss base
45.00
kev bonus
0.00
epss bonus
0.00
poc bonus
0.00
raw before weight
45.00
industry weight
1.21
freshness factor
0.50
exploitability factor
1.00
days old
38.00
vendor mismatch penalty
0.00
consensus penalty
-3.00

Path: operational

Consensus check

The pipeline self-checks before delivery. These rules lowered the score:

  • TTP_SKIPPED TTP mapping skipped (placeholder or aggregation article) −3
Consensus penalty:
−3.0
Total penalty:
−3.0
ESC