Executive brief
A security vulnerability has been identified in Microsoft Excel, the widely used spreadsheet application. This flaw allows an unauthorized person to access sensitive information remotely over a network. Such an exploit could lead to the exposure of confidential business data or internal system details, potentially aiding further attacks against the organization.
Technical details
This vulnerability is classified as an out-of-bounds read (CWE-125) within Microsoft Office Excel. The flaw occurs when the application reads data past the end of the intended buffer, which can be triggered by a remote, unauthenticated attacker over a network. According to the CVSS metrics, the attack requires no special privileges and no user interaction, making it highly accessible. Successful exploitation results in high confidentiality impact, allowing the attacker to disclose memory contents or sensitive information from the affected system. Microsoft has released information regarding this vulnerability via their Security Update Guide.
Affected products
- Microsoft Excel
Timeline
- 2026-06-09: disclosed: Initial publication of the CVE record.
- 2026-06-09: advisory: Microsoft released the security advisory.