Junglewise Threat Intelligence

CVE-2026-55041: Microsoft Excel heap buffer overflow code execution

CVE-2026-55041 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2024, Microsoft Office 365 for Mac, Microsoft Excel 2016, Microsoft Office Online Server, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021, Microsoft 365 Apps for Enterprise, Microsoft Office 2019. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in Microsoft Excel that could allow an attacker to take control of a user's computer. This occurs when a user is tricked into opening a specially crafted, malicious Excel file. If successful, the attacker could gain the same permissions as the current user, potentially leading to data theft or the installation of unauthorized software.

Technical details

A heap-based buffer overflow vulnerability (CWE-122) exists in Microsoft Office Excel across multiple versions, including Office 2019, 2021, 2024, and Microsoft 365 Apps. The vulnerability is triggered when the application fails to properly validate input while processing a specially crafted Excel file. An attacker can exploit this by convincing a user to open a malicious file, leading to arbitrary code execution in the context of the current user. The attack vector is local, requiring user interaction (UI:R), but does not require prior administrative privileges (PR:N). Microsoft has released security updates to address this issue.

Affected products

  • Microsoft 365 Apps for Enterprise < 16.0.1 (See aka.ms/OfficeSecurityReleases)
  • Microsoft Excel 2016 16.0.0.0 to < 16.0.5561.1001
  • Microsoft Office 2019 < 19.0.0 (See aka.ms/OfficeSecurityReleases)
  • Microsoft Office 365 for Mac 1.0.0 to < 16.111.26071215
  • Microsoft Office LTSC 2021 < 16.0.1 (See aka.ms/OfficeSecurityReleases)
  • Microsoft Office LTSC 2024 < 16.0.0 (See aka.ms/OfficeSecurityReleases)
  • Microsoft Office LTSC for Mac 2021 < 16.0.1 (See aka.ms/OfficeSecurityReleases)
  • Microsoft Office LTSC for Mac 2024 < 16.0.0 (See aka.ms/OfficeSecurityReleases)
  • Microsoft Office Online Server 16.0.0.0 to < 16.0.10417.20175

Timeline

  • 2026-07-14: advisory: Initial advisory published by Microsoft and NVD.
  • 2026-07-14: patched: Security updates made available via Microsoft Update Guide.

References

Related threats