Executive brief
A security vulnerability exists in Microsoft Excel, the widely used spreadsheet application. An attacker could exploit this flaw by tricking a user into opening a specially crafted file, potentially allowing the attacker to take control of the user's computer. This could lead to the theft of sensitive data, unauthorized software installation, or disruption of business operations.
Technical details
A heap-based buffer overflow (CWE-122) exists in Microsoft Excel due to improper validation of user-supplied data when parsing spreadsheet files. The vulnerability is triggered when a user opens a maliciously crafted Excel file. Although the attack vector is local, it requires no prior privileges (PR:N) but does require user interaction (UI:R). Successful exploitation allows an attacker to execute arbitrary code in the context of the current user, potentially leading to full system compromise. Microsoft has released security updates to address this issue across various versions of Office and Excel.
Affected products
- Microsoft Microsoft Excel 2016 16.0.0.0 to 16.0.5561.1001
- Microsoft Microsoft 365 Apps for Enterprise 16.0.1 to latest security release
- Microsoft Microsoft Office 2019 19.0.0 to latest security release
- Microsoft Microsoft Office 365 for Mac 1.0.0 to 16.111.26071215
- Microsoft Microsoft Office LTSC 2021 16.0.1 to latest security release
- Microsoft Microsoft Office LTSC 2024 16.0.0 to latest security release
- Microsoft Office Online Server 16.0.0.0 to 16.0.10417.20175
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory