Executive brief
Microsoft Excel, a widely used spreadsheet application, contains a security vulnerability that could allow an attacker to take control of a user's computer. To exploit this, an attacker would typically need to trick a user into opening a specially crafted malicious Excel file. If successful, the attacker could run unauthorized programs, access sensitive data, or disrupt business operations on the affected machine.
Technical details
A vulnerability classified as an out-of-bounds read (CWE-125) exists in multiple versions of Microsoft Excel and Office suites. The flaw is triggered when the application fails to properly validate input while reading data from a file, leading to memory corruption. An attacker can exploit this by convincing a user to open a maliciously crafted Excel document. Successful exploitation grants the attacker the ability to execute arbitrary code in the context of the current user. Affected products include Excel 2016, Office 2019, Office LTSC 2021/2024, and Microsoft 365 Apps across Windows and Mac platforms. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Excel 2016 versions before 16.0.5561.1001
- Microsoft Office 2019 versions before July 2024 update
- Microsoft Office LTSC 2021 versions before July 2024 update
- Microsoft Office LTSC 2024 versions before July 2024 update
- Microsoft 365 Apps for Enterprise versions before July 2024 update
- Microsoft Office 365 for Mac versions before 16.111.26071215
- Microsoft Office Online Server versions before 16.0.10417.20175
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory: Microsoft released security updates for affected products.