Executive brief
A security vulnerability exists in Microsoft Excel, the widely used spreadsheet application. If a user is tricked into opening a specially crafted malicious file, an attacker could gain the ability to run unauthorized code on the user's computer. This could lead to the theft of sensitive data, system instability, or full control over the affected workstation.
Technical details
A heap-based buffer overflow (CWE-122) exists in multiple versions of Microsoft Excel and Office products. The vulnerability is triggered when the application processes a specially crafted file, leading to memory corruption. An attacker can exploit this by convincing a user to open a malicious document (User Interaction required). Successful exploitation allows for local arbitrary code execution with the privileges of the current user. Microsoft has released security updates to address this issue across affected platforms including Windows and macOS.
Affected products
- Microsoft Microsoft 365 Apps for Enterprise 16.0.1 and later versions prior to security release
- Microsoft Microsoft Excel 2016 16.0.0.0 to 16.0.5561.1001
- Microsoft Microsoft Office 2019 19.0.0 and later versions prior to security release
- Microsoft Microsoft Office 365 for Mac 1.0.0 to 16.111.26071215
- Microsoft Microsoft Office LTSC 2021 16.0.1 and later versions prior to security release
- Microsoft Microsoft Office LTSC 2024 16.0.0 and later versions prior to security release
- Microsoft Microsoft Office LTSC for Mac 2021 16.0.1 to 16.111.26071215
- Microsoft Microsoft Office LTSC for Mac 2024 16.0.0 to 16.111.26071215
- Microsoft Office Online Server 16.0.0.0 to 16.0.10417.20175
Timeline
- 2026-07-14: disclosed: Initial publication of the CVE record
- 2026-07-14: advisory: Microsoft released security update guide details