Executive brief
A security vulnerability exists in Microsoft Excel, the widely used spreadsheet application. An attacker could exploit this flaw by tricking a user into opening a specially crafted file, potentially leading to the unauthorized disclosure of sensitive information from the computer's memory. This could result in a loss of data confidentiality or provide a stepping stone for further attacks on the system.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in Microsoft Office Excel. The flaw is triggered when the application fails to properly validate input while processing a crafted Excel file. An attacker can exploit this by convincing a local user to open a malicious document, allowing the attacker to read sensitive information from the process memory. According to the CVSS vector, while the attack is local and requires user interaction, it can lead to high impacts on confidentiality, integrity, and availability. Microsoft has released information regarding this vulnerability via their Security Update Guide.
Affected products
- Microsoft Office Excel
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory: Published by Microsoft and NVD