CVE-2024-49029 is a high-severity Remote Code Execution vulnerability affecting Microsoft Excel, Microsoft Office, and Microsoft 365 Apps. An attacker could exploit this vulnerability by tricking a user into opening a specially crafted Excel file, leading to full compromise of the affected system (Confidentiality, Integrity, Availability impacts are High). While the CVSS score is 7.8, its EPSS score is low, suggesting a low probability of exploitation in the wild. Currently, there is no public exploit code available, and it is not listed on CISA's KEV catalog, indicating no active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:excel:2016:*:*:*:*:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2019:*:*:*:*:*:*:* | ||
2021CPE matchmatch criteria | cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:-:*:* | ||
2021CPE matchmatch criteria | cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:macos:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.