Executive brief
Microsoft Excel is affected by a security vulnerability that could allow an attacker to run malicious code on a user's computer. This typically occurs if a user is tricked into opening a specially crafted Excel file. If successful, an attacker could gain the same permissions as the local user, potentially leading to data theft, unauthorized system changes, or further malware installation.
Technical details
This vulnerability is classified as an integer overflow or wraparound (CWE-190) which leads to a heap-based buffer overflow (CWE-122) within Microsoft Excel. The attack vector is local, requiring a user to interact with a malicious file (User Interaction: Required). Successful exploitation allows an unauthorized attacker to execute arbitrary code in the context of the current user. The vulnerability affects multiple versions of Microsoft Office, including Office 2016, 2019, LTSC 2021/2024, and Microsoft 365 Apps on both Windows and macOS platforms. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Microsoft 365 Apps for Enterprise < 16.0.1 (see aka.ms/OfficeSecurityReleases)
- Microsoft Microsoft Excel 2016 < 16.0.5561.1001
- Microsoft Microsoft Office 2019 < 19.0.0 (see aka.ms/OfficeSecurityReleases)
- Microsoft Microsoft Office 365 for Mac < 16.111.26071215
- Microsoft Microsoft Office LTSC 2021 < 16.0.1 (see aka.ms/OfficeSecurityReleases)
- Microsoft Microsoft Office LTSC 2024 < 16.0.0 (see aka.ms/OfficeSecurityReleases)
- Microsoft Microsoft Office LTSC for Mac 2021 < 16.111.26071215
- Microsoft Microsoft Office LTSC for Mac 2024 < 16.111.26071215
- Microsoft Office Online Server < 16.0.10417.20175
Timeline
- 2026-07-14: advisory: Initial publication by Microsoft and NVD
- 2026-07-14: patched: Security updates made available via Microsoft Update Guide