Executive brief
Microsoft Excel is a widely used spreadsheet application for data analysis and business reporting. A security vulnerability has been identified that could allow an attacker to access sensitive information or cause the application to crash if a user opens a specially crafted file. This could lead to the exposure of private data or a disruption in business operations for users working with Excel documents.
Technical details
This vulnerability is classified as an out-of-bounds read (CWE-125) within Microsoft Office Excel. The flaw occurs when the application reads data past the end of the intended buffer while processing a malicious file. An attacker can exploit this by convincing a user to open a specially crafted Excel document (requiring user interaction). Successful exploitation can lead to the disclosure of sensitive information from the application's memory or a denial-of-service condition (application crash). The vulnerability affects multiple versions of Excel across Windows and macOS, as well as Office Online Server.
Affected products
- Microsoft Microsoft 365 Apps for Enterprise 16.0.1 to latest security release
- Microsoft Microsoft Excel 2016 16.0.0.0 to 16.0.5561.1001
- Microsoft Microsoft Office 2019 19.0.0 to latest security release
- Microsoft Microsoft Office 365 for Mac 1.0.0 to 16.111.26071215
- Microsoft Microsoft Office LTSC 2021 16.0.1 to latest security release
- Microsoft Microsoft Office LTSC 2024 16.0.0 to latest security release
- Microsoft Microsoft Office LTSC for Mac 2021 16.0.1 to 16.111.26071215
- Microsoft Microsoft Office LTSC for Mac 2024 16.0.0 to 16.111.26071215
- Microsoft Office Online Server 16.0.0.0 to 16.0.10417.20175
Timeline
- 2026-07-14: disclosed: Initial publication by Microsoft and NVD