Junglewise Threat Intelligence

CVE-2026-55024: Microsoft Excel type confusion code execution

CVE-2026-55024 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Office LTSC 2024, Microsoft Office 365 for Mac, Microsoft Excel 2016, Microsoft Office Online Server, Microsoft Office LTSC 2021, Microsoft 365 Apps for Enterprise, Microsoft Office 2019. Vendors: Microsoft.

Executive brief

Microsoft Excel, a widely used spreadsheet application, contains a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker would typically need to trick a user into opening a specially crafted malicious file. If successful, the attacker could run unauthorized software, access sensitive data, or disrupt business operations on the affected machine.

Technical details

A type confusion vulnerability (CWE-843) exists in Microsoft Office Excel due to the application accessing resources using an incompatible type. The vulnerability is triggered when the application processes a specially crafted file, leading to memory corruption. An attacker can exploit this by convincing a user to open a malicious Excel document, resulting in arbitrary code execution in the context of the current user. The attack vector is local, but requires user interaction (UI:R). Microsoft has released security updates to address this issue across various versions of Office, including Office 2016, 2019, LTSC, and Microsoft 365 Apps.

Affected products

  • Microsoft Excel 2016 < 16.0.5561.1001
  • Microsoft Office 2019 All versions
  • Microsoft Office LTSC 2021 All versions
  • Microsoft Office LTSC 2024 All versions
  • Microsoft 365 Apps for Enterprise All versions
  • Microsoft Office 365 for Mac < 16.111.26071215
  • Microsoft Office Online Server < 16.0.10417.20175

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats