Executive brief
A security vulnerability exists in Microsoft Excel, the widely used spreadsheet application. If a user opens a specially crafted malicious file, an attacker could gain the ability to run unauthorized commands or software on the victim's computer. This could lead to a full system compromise, data theft, or the installation of malware.
Technical details
A heap-based buffer overflow vulnerability (CWE-122) exists within Microsoft Office Excel. The flaw is triggered when the application fails to properly validate or bounds-check data while processing a specially crafted Excel file. An attacker can exploit this by tricking a user into opening a malicious document, leading to arbitrary code execution in the context of the current user. The attack vector is local, requiring user interaction (UI:R), and carries a CVSS base score of 7.8 due to the high impact on confidentiality, integrity, and availability.
Affected products
- Microsoft Office Excel
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory: Published by Microsoft and NVD