Junglewise Threat Intelligence

CVE-2026-47642: Microsoft Office Excel use after free code execution

CVE-2026-47642 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Office LTSC 2024, Microsoft Office 365 for Mac, Microsoft Office Online Server, Microsoft Office LTSC 2021, Microsoft 365 Apps for Enterprise, Microsoft Office 2019. Vendors: Microsoft.

Executive brief

Microsoft Excel, a widely used spreadsheet application, contains a security vulnerability that could allow an attacker to take control of a user's computer. To exploit this, an attacker would typically need to trick a user into opening a specially crafted malicious Excel file. If successful, the attacker could run unauthorized software, access sensitive data, or disrupt business operations on the affected system.

Technical details

A use-after-free vulnerability (CWE-416) exists in Microsoft Office Excel due to improper memory management during file processing. The vulnerability is triggered when the application attempts to access memory that has already been freed, which can be leveraged by an attacker to achieve arbitrary code execution. The attack vector is local, requiring a user to interact with a malicious document (User Interaction: Required). Successful exploitation allows the attacker to execute code with the privileges of the current user. Microsoft has released security updates to address this issue across various versions of Office, including Microsoft 365 Apps, Office LTSC, and Office Online Server.

Affected products

  • Microsoft Microsoft 365 Apps for Enterprise 16.0.1 and later versions prior to the July 2026 security update
  • Microsoft Microsoft Office 2019 19.0.0 and later versions prior to the July 2026 security update
  • Microsoft Microsoft Office 365 for Mac 1.0.0 to 16.111.26071215
  • Microsoft Microsoft Office LTSC 2021 16.0.1 and later versions prior to the July 2026 security update
  • Microsoft Microsoft Office LTSC 2024 16.0.0 and later versions prior to the July 2026 security update
  • Microsoft Office Online Server 16.0.0.0 to 16.0.10417.20175

Timeline

  • 2026-07-14: disclosed: CVE published by Microsoft and NVD
  • 2026-07-14: advisory: Microsoft Security Update Guide published

References

Related threats