Executive brief
A security vulnerability exists in Microsoft Excel that could allow an attacker to access sensitive information on a user's computer. To exploit this, an attacker would need to trick a user into opening a specially crafted file. This could lead to the unauthorized disclosure of private data stored in the system's memory.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in Microsoft Office Excel across multiple versions, including Office 2019, 2021, 2024, and Microsoft 365 Apps. The flaw is triggered when the application fails to properly validate input, allowing a local attacker to read data outside of the intended buffer. Exploitation requires a user to open a malicious file (User Interaction: Required). Successful exploitation allows the attacker to disclose sensitive information from the process memory. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Microsoft 365 Apps for Enterprise 16.0.1 up to Office Security Releases
- Microsoft Microsoft Excel 2016 16.0.0.0 to 16.0.5561.1001
- Microsoft Microsoft Office 2019 19.0.0 up to Office Security Releases
- Microsoft Microsoft Office 365 for Mac 1.0.0 to 16.111.26071215
- Microsoft Microsoft Office LTSC 2021 16.0.1 up to Office Security Releases
- Microsoft Microsoft Office LTSC 2024 16.0.0 up to Office Security Releases
- Microsoft Microsoft Office LTSC for Mac 2021 16.0.1 to 16.111.26071215
- Microsoft Microsoft Office LTSC for Mac 2024 16.0.0 to 16.111.26071215
- Microsoft Office Online Server 16.0.0.0 to 16.0.10417.20175
Timeline
- 2026-07-14: advisory: Initial advisory published by Microsoft and NVD.