Executive brief
A remote code execution vulnerability exists in Microsoft Excel when the software fails to properly handle objects in memory. An attacker could exploit this to execute arbitrary code in the context of the current user.
Affected products
- Microsoft Excel 2010 Service Pack 2
- Microsoft Excel 2013 Service Pack 1
- Microsoft Excel 2016
- Microsoft Office 2016 for Mac
- Microsoft Office 2019
- Microsoft Office 2019 for Mac
- Microsoft Office 365 ProPlus
Timeline
- 2019-09-11: disclosed: NVD Published Date
- 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-03-17: other: CISA Due Date for remediation