Executive brief
Microsoft Excel is a widely used spreadsheet application for data analysis and reporting. A security vulnerability has been identified that could allow an attacker to run malicious code on a user's computer if the user is tricked into opening a specially crafted Excel file. This could lead to a full compromise of the user's workstation, including the theft of sensitive data or the installation of malware.
Technical details
A type confusion vulnerability (CWE-843) exists in Microsoft Office Excel due to the application accessing resources using an incompatible type. The vulnerability is triggered when a user opens a maliciously crafted Excel file. While the attack vector is classified as local, it requires user interaction (UI:R) to execute. Successful exploitation allows an attacker to achieve arbitrary code execution in the context of the current user. Microsoft has released security updates to address this issue across various versions of Office, including Microsoft 365 Apps, Office LTSC, and Office Online Server.
Affected products
- Microsoft Microsoft 365 Apps for Enterprise versions prior to July 2026 updates
- Microsoft Microsoft Excel 2016 versions prior to 16.0.5561.1001
- Microsoft Microsoft Office 2019 versions prior to July 2026 updates
- Microsoft Microsoft Office 365 for Mac versions prior to 16.111.26071215
- Microsoft Microsoft Office LTSC 2021 versions prior to July 2026 updates
- Microsoft Microsoft Office LTSC 2024 versions prior to July 2026 updates
- Microsoft Office Online Server versions prior to 16.0.10417.20175
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory