CVE-2024-49029

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Nov 12, 2024
Updated: Nov 16, 2024
CWE ID 908

Summary

CVE-2024-49029 is a newly disclosed Remote Code Execution vulnerability affecting Microsoft Excel. This issue grants attackers the ability to execute arbitrary code on a victim's system by manipulating specially crafted Excel files. Successful exploitation could lead to the installation of malware, unauthorized system access, or data theft. Microsoft recommends users update their Excel software to the latest version to mitigate this risk. It's crucial for organizations to enforce safe file handling practices and implement robust email security measures to prevent potential attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Office
  • Microsoft Office Excel

Affected Vendors

  • Microsoft