Junglewise Threat Intelligence

CVE-2026-55053: Microsoft Excel heap buffer overflow code execution

CVE-2026-55053 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2024, Microsoft Office 365 for Mac, Microsoft Excel 2016, Microsoft Office Online Server, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021, Microsoft 365 Apps for Enterprise, Microsoft Office 2019. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in Microsoft Excel, the widely used spreadsheet application. An attacker could exploit this flaw by tricking a user into opening a specially crafted file, potentially allowing the attacker to take control of the user's computer. This could lead to the theft of sensitive data, unauthorized changes to files, or a complete disruption of business operations on the affected machine.

Technical details

This vulnerability is a heap-based buffer overflow (CWE-122) within Microsoft Excel. The flaw is triggered when the application processes a specially crafted file, leading to memory corruption. While the attack vector is classified as local, it requires user interaction (UI:R), typically involving a victim opening a malicious spreadsheet provided by the attacker. Successful exploitation allows for arbitrary code execution in the context of the current user. Microsoft has released security updates to address this issue across various versions of Office, including LTSC and Microsoft 365 Apps.

Affected products

  • Microsoft Microsoft 365 Apps for Enterprise 16.0.1 to latest security release
  • Microsoft Microsoft Excel 2016 16.0.0.0 to 16.0.5561.1001
  • Microsoft Microsoft Office 2019 19.0.0 to latest security release
  • Microsoft Microsoft Office 365 for Mac 1.0.0 to 16.111.26071215
  • Microsoft Microsoft Office LTSC 2021 16.0.1 to latest security release
  • Microsoft Microsoft Office LTSC 2024 16.0.0 to latest security release
  • Microsoft Microsoft Office LTSC for Mac 2021 16.0.1 to 16.111.26071215
  • Microsoft Microsoft Office LTSC for Mac 2024 16.0.0 to 16.111.26071215
  • Microsoft Office Online Server 16.0.0.0 to 16.0.10417.20175

Timeline

  • 2026-07-14: advisory: Initial disclosure by Microsoft and NVD publication.
  • 2026-07-14: patched: Security updates made available via the Microsoft Update Guide.

References

Related threats