Junglewise Threat Intelligence

CVE-2026-48580: Microsoft Excel untrusted pointer dereference information disclosure

CVE-2026-48580 · Severity: medium · CVSS 5.5 · Published 2026-07-14

Technologies: Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2024, Microsoft Office 365 for Mac, Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office Online Server, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021, Microsoft Office 2019. Vendors: Microsoft.

Executive brief

A security vulnerability exists in Microsoft Excel, the widely used spreadsheet application. An attacker could exploit this flaw to gain unauthorized access to sensitive information stored on a user's computer. To be successful, the attacker must convince a user to open a specially crafted file.

Technical details

An untrusted pointer dereference vulnerability (CWE-822) exists in Microsoft Office Excel. The flaw is triggered when the application processes a specially crafted file containing malicious pointer data. An attacker can exploit this by convincing a local user to open the malicious file, leading to unauthorized information disclosure from the system's memory. The vulnerability affects multiple versions of Office, including Microsoft 365 Apps, Excel 2016, and Office LTSC for both Windows and Mac. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Microsoft 365 Apps for Enterprise < 16.0.1
  • Microsoft Microsoft Excel 2016 < 16.0.5561.1001
  • Microsoft Microsoft Office 2019 < 19.0.0
  • Microsoft Microsoft Office 365 for Mac < 16.111.26071215
  • Microsoft Microsoft Office LTSC 2021 < 16.0.1
  • Microsoft Microsoft Office LTSC 2024 < 16.0.0
  • Microsoft Microsoft Office LTSC for Mac 2021 < 16.0.1
  • Microsoft Microsoft Office LTSC for Mac 2024 < 16.0.0
  • Microsoft Office Online Server < 16.0.10417.20175

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats