Executive brief
A security vulnerability exists in Microsoft Excel, the widely used spreadsheet application. If a user is tricked into opening a specially crafted malicious file, an attacker could gain the ability to run unauthorized code on the user's computer. This could lead to the theft of sensitive data, installation of malware, or full system compromise.
Technical details
A heap-based buffer overflow vulnerability (CWE-122) exists in Microsoft Office Excel. The flaw is triggered when the application fails to properly validate input while processing a specially crafted file. An attacker can exploit this by convincing a user to open a malicious document, leading to arbitrary code execution in the context of the current user. The attack vector is local, requiring user interaction (UI:R), and affects multiple versions of Office across Windows and macOS platforms. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Microsoft Excel 2016 16.0.0.0 to 16.0.5561.1001
- Microsoft Microsoft 365 Apps for Enterprise 16.0.1 and later
- Microsoft Microsoft Office 2019 19.0.0 and later
- Microsoft Microsoft Office 365 for Mac 1.0.0 to 16.111.26071215
- Microsoft Microsoft Office LTSC 2021 16.0.1 and later
- Microsoft Microsoft Office LTSC 2024 16.0.0 and later
- Microsoft Microsoft Office LTSC for Mac 2021 16.0.1 to 16.111.26071215
- Microsoft Microsoft Office LTSC for Mac 2024 16.0.0 to 16.111.26071215
- Microsoft Office Online Server 16.0.0.0 to 16.0.10417.20175
Timeline
- 2026-07-14: advisory: Initial publication by Microsoft and NVD
- 2026-07-14: disclosed