Executive brief
Microsoft Excel, a widely used spreadsheet application, contains a security vulnerability that could allow an attacker to run malicious code on a user's computer. To exploit this, an attacker would typically need to trick a user into opening a specially crafted Excel file. Successful exploitation could lead to a full system compromise, allowing the attacker to steal data, install software, or disrupt business operations.
Technical details
An integer underflow (wraparound) vulnerability exists in Microsoft Office Excel, which can lead to an out-of-bounds memory access (CWE-125). The vulnerability is triggered when the application processes a malformed Excel file. An attacker can exploit this by convincing a user to open a malicious document, leading to arbitrary code execution in the context of the current user. The attack vector is local with a requirement for user interaction (UI:R), and it carries a high impact on confidentiality, integrity, and availability. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Excel
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory: Published by Microsoft and NVD