Executive brief
A security vulnerability has been identified in Microsoft Excel, the widely used spreadsheet application. An attacker could exploit this flaw to run unauthorized code on a user's computer, typically by tricking them into opening a specially crafted Excel file. This could lead to a full system compromise, allowing the attacker to steal sensitive data, install malware, or disrupt business operations.
Technical details
A use-after-free vulnerability (CWE-416) exists in Microsoft Office Excel. The flaw is triggered when the application attempts to use memory that has already been deallocated, leading to memory corruption. An attacker can exploit this by convincing a user to open a maliciously crafted Excel document. Successful exploitation requires user interaction but no prior administrative privileges, allowing the attacker to execute arbitrary code with the same permissions as the logged-in user. Microsoft has released information regarding this vulnerability in their security update guide.
Affected products
- Microsoft Excel
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory