Junglewise Threat Intelligence

CVE-2026-45469: Microsoft Office Excel integer underflow code execution

CVE-2026-45469 · Severity: high · CVSS 7.8 · Published 2026-06-09

Technologies: Microsoft Excel. Vendors: Microsoft.

Executive brief

Microsoft Excel, a widely used spreadsheet application, contains a security vulnerability that could allow an attacker to take control of a user's computer. To exploit this, an attacker would typically need to trick a user into opening a specially crafted, malicious Excel file. Successful exploitation could lead to the unauthorized installation of programs, data theft, or full system compromise.

Technical details

An integer underflow (CWE-191) and subsequent heap-based buffer overflow (CWE-122) exist in Microsoft Office Excel. The vulnerability is triggered when the application processes a specially crafted file, leading to memory corruption. While the attack vector is classified as local, it typically requires user interaction (UI:R), such as a user opening a malicious document received via email or downloaded from the web. Successful exploitation allows for arbitrary code execution in the context of the current user. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Excel

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats