Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 15
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Microsoft 365_Apps
cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:*
|
— | — |
|
Microsoft 365_Apps
cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:*
|
— | — |
|
Microsoft Excel
cpe:2.3:a:microsoft:excel:2016:*:*:*:*:*:x64:*
|
— | — |
|
Microsoft Excel
cpe:2.3:a:microsoft:excel:2016:*:*:*:*:*:x86:*
|
— | — |
|
Microsoft Microsoft_365
cpe:2.3:a:microsoft:microsoft_365:-:*:*:*:*:macos:*:*
|
— | — |
|
Microsoft Office_2016
cpe:2.3:a:microsoft:office_2016:-:*:*:*:-:*:x64:*
|
— | — |
|
Microsoft Office_2016
cpe:2.3:a:microsoft:office_2016:-:*:*:*:-:*:x86:*
|
— | — |
|
Microsoft Office_2019
cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x64:*
|
— | — |
|
Microsoft Office_2019
cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x86:*
|
— | — |
|
Microsoft Office_2021
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x64:*
|
— | — |
|
Microsoft Office_2021
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x86:*
|
— | — |
|
Microsoft Office_2021
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:macos:-:*
|
— | — |
|
Microsoft Office_2024
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x64:*
|
— | — |
|
Microsoft Office_2024
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x86:*
|
— | — |
|
Microsoft Office_2024
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:macos:-:*
|
— | — |