Description
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
E
Unchanged
RL
O
RC
Changed
Affected products
- microsoft / 365_apps
- microsoft / 365_apps
- microsoft / Excel2016 – 2016
- microsoft / Excel2016 – 2016
- microsoft / microsoft_365
- microsoft / Microsoft 365 Apps for Enterprise16.0.1 – https://aka.ms/OfficeSecurityReleases
- microsoft / Microsoft Excel 201616.0.0.0 – 16.0.5565.1001
- microsoft / Microsoft Office 201919.0.0 – https://aka.ms/OfficeSecurityReleases
- microsoft / Microsoft Office 365 for Mac1.0.0 – 16.112.26081010
- microsoft / Microsoft Office LTSC 202116.0.1 – https://aka.ms/OfficeSecurityReleases
- microsoft / Microsoft Office LTSC 202416.0.0 – https://aka.ms/OfficeSecurityReleases
- microsoft / Microsoft Office LTSC for Mac 202116.0.1 – 16.112.26081010
- microsoft / Microsoft Office LTSC for Mac 202416.0.0 – 16.112.26081010
- microsoft / office_2019
- microsoft / office_2019
- microsoft / office_2021
- microsoft / office_2021
- microsoft / office_2021
- microsoft / office_2024
- microsoft / office_2024
- microsoft / office_2024
- microsoft / Office Online Server16.0.0.0 – 16.0.10417.20175
References
Updated 23m ago · 8 sources