Executive brief
Microsoft Excel, a widely used spreadsheet application, contains a vulnerability that could allow an attacker to run malicious code on a user's computer. To exploit this, an attacker would typically need to trick a user into opening a specially crafted Excel file. If successful, the attacker could gain the same permissions as the local user, potentially leading to data theft, unauthorized system changes, or further malware installation.
Technical details
A use-after-free (CWE-416) vulnerability exists in Microsoft Office Excel due to improper memory management. An attacker can exploit this by convincing a user to open a maliciously crafted Excel document, which triggers the vulnerability when the application attempts to access memory that has already been freed. This is a local attack vector requiring user interaction (UI:R). Successful exploitation allows for arbitrary code execution in the context of the current user. Microsoft has released security updates to address this issue across various versions of Office, including Microsoft 365 Apps, Office LTSC, and Office Online Server.
Affected products
- Microsoft Microsoft 365 Apps for Enterprise 16.0.1 and later versions
- Microsoft Microsoft Office 2019 19.0.0 and later versions
- Microsoft Microsoft Office 365 for Mac Prior to 16.111.26071215
- Microsoft Microsoft Office LTSC 2021 16.0.1 and later versions
- Microsoft Microsoft Office LTSC 2024 16.0.0 and later versions
- Microsoft Office Online Server Prior to 16.0.10417.20175
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory