Executive brief
A security vulnerability has been identified in Microsoft Excel, the widely used spreadsheet application. If a user is tricked into opening a specially crafted malicious file, an attacker could gain the ability to run unauthorized code on the user's computer. This could lead to the theft of sensitive data, system instability, or full control over the affected workstation.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in Microsoft Office Excel due to improper validation of input data when parsing spreadsheet files. The attack vector is local, requiring a user to open a specially crafted file (User Interaction required). Successful exploitation allows an attacker to bypass memory protections and achieve arbitrary code execution in the context of the current user. Microsoft has released security updates for affected versions including Excel 2016, Office 2019, LTSC versions, and Microsoft 365 Apps.
Affected products
- Microsoft Microsoft 365 Apps for Enterprise < 16.0.1
- Microsoft Microsoft Excel 2016 < 16.0.5561.1001
- Microsoft Microsoft Office 2019 < 19.0.0
- Microsoft Microsoft Office 365 for Mac < 16.111.26071215
- Microsoft Microsoft Office LTSC 2021 < 16.0.1
- Microsoft Microsoft Office LTSC 2024 < 16.0.0
- Microsoft Microsoft Office LTSC for Mac 2021 < 16.111.26071215
- Microsoft Microsoft Office LTSC for Mac 2024 < 16.111.26071215
- Microsoft Office Online Server < 16.0.10417.20175
Timeline
- 2026-07-14: advisory: Initial publication by Microsoft and NVD