Executive brief
Microsoft Excel, a widely used spreadsheet application, contains a security vulnerability that could allow an attacker to access sensitive information. To exploit this, an attacker would typically need to trick a user into opening a specially crafted file. Successful exploitation could lead to the unauthorized disclosure of data from the user's system or memory.
Technical details
This vulnerability is classified as an out-of-bounds read (CWE-125) within Microsoft Excel. The flaw occurs when the application processes a specially crafted file, leading to memory access outside of the intended buffer. An attacker can exploit this by hosting a malicious file and convincing a user to open it (User Interaction required). Successful exploitation allows the attacker to read sensitive information from the process memory, which could be used to bypass security mitigations or facilitate further attacks. Microsoft has released security updates to address this issue across affected Office versions.
Affected products
- Microsoft 365 Apps for Enterprise versions prior to July 2026 updates
- Microsoft Excel 2016 < 16.0.5561.1001
- Microsoft Office 2019 versions prior to July 2026 updates
- Microsoft Office 365 for Mac < 16.111.26071215
- Microsoft Office LTSC 2021 versions prior to July 2026 updates
- Microsoft Office LTSC 2024 versions prior to July 2026 updates
- Microsoft Office LTSC for Mac 2021 < 16.111.26071215
- Microsoft Office LTSC for Mac 2024 < 16.111.26071215
- Microsoft Office Online Server < 16.0.10417.20175
Timeline
- 2026-07-14: advisory: Initial disclosure by Microsoft and NVD publication.
- 2026-07-14: patched: Security updates made available via Microsoft Security Update Guide.