Junglewise Threat Intelligence

CVE-2026-44817: Microsoft Office Excel integer underflow code execution

CVE-2026-44817 · Severity: high · CVSS 7.8 · Published 2026-06-09

Technologies: Microsoft Excel. Vendors: Microsoft.

Executive brief

Microsoft Excel, a widely used spreadsheet application, contains a security vulnerability that could allow an attacker to take control of a user's computer. To exploit this, an attacker would typically need to trick a user into opening a specially crafted malicious Excel file. Successful exploitation could lead to the unauthorized installation of programs, data theft, or full system compromise.

Technical details

An integer underflow (wraparound) vulnerability exists in Microsoft Office Excel. The flaw is triggered when the application processes a specially crafted file, leading to memory corruption or type confusion (CWE-843). While the attack vector is local, it requires user interaction, such as opening a malicious document. Successful exploitation allows an unauthenticated attacker to execute arbitrary code with the privileges of the current user. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Excel

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats