Executive brief
A security vulnerability exists in Microsoft Excel, the widely used spreadsheet application. An attacker could exploit this flaw by tricking a user into opening a specially crafted file, potentially leading to the unauthorized disclosure of sensitive information or causing the application to crash. This could impact data confidentiality and disrupt business operations for users working with financial or corporate data.
Technical details
A heap-based buffer overflow (CWE-122) exists in multiple versions of Microsoft Excel, including Office 2016, 2019, LTSC 2021/2024, and Microsoft 365 Apps. The vulnerability is triggered when the application fails to properly validate input while processing a malicious file. An attacker can exploit this locally by convincing a user to open a crafted document (User Interaction required). Successful exploitation can lead to local information disclosure, limited integrity impact, and high impact on availability (application crash). Microsoft has released security updates to address this issue across affected platforms.
Affected products
- Microsoft Excel 2016 < 16.0.5561.1001
- Microsoft Office 2019 All versions
- Microsoft Office LTSC 2021 All versions
- Microsoft Office LTSC 2024 All versions
- Microsoft 365 Apps for Enterprise All versions
- Microsoft Office 365 for Mac < 16.111.26071215
- Microsoft Office Online Server < 16.0.10417.20175
Timeline
- 2026-07-14: disclosed: Initial publication of the CVE record.
- 2026-07-14: advisory: Microsoft released the security update guide for this vulnerability.