CVE-2022-30173 is a Microsoft Excel Remote Code Execution Vulnerability affecting Microsoft Excel and Office Web Apps Server. With a CVSS score of 7.8 (High), it requires user interaction (UI:R) for an attacker to achieve high impact on confidentiality, integrity, and availability (C:H/I:H/A:H) through a local attack vector (AV:L). While not currently listed in CISA's KEV catalog, there is no public exploit code available (Metasploit, Nuclei, ExploitDB: None), and community discussion and media coverage are minimal, suggesting low current exploitation activity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:excel:2013:sp1:*:*:*:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:excel:2013:sp1:*:*:rt:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:excel:2016:*:*:*:*:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:office_web_apps_server:2013:sp1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.