Executive brief
A security vulnerability exists in Microsoft Excel, the widely used spreadsheet application. If a user is tricked into opening a specially crafted file, an attacker could gain access to sensitive information stored in the computer's memory or cause the application to crash. This could lead to the exposure of confidential data or disrupt business operations by making the software unavailable.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in Microsoft Excel due to improper validation of data when parsing specially crafted files. An attacker can exploit this by convincing a user to open a malicious Excel file, leading to the disclosure of sensitive information from the process memory or an application crash (denial of service). The attack vector is local, but requires user interaction (UI:R) to trigger the flaw. Affected products include various versions of Microsoft Office, Excel 2016, and Office Online Server. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Microsoft 365 Apps for Enterprise versions prior to July 2026 updates
- Microsoft Microsoft Excel 2016 versions prior to 16.0.5561.1001
- Microsoft Microsoft Office 2019 versions prior to July 2026 updates
- Microsoft Microsoft Office 365 for Mac versions prior to 16.111.26071215
- Microsoft Microsoft Office LTSC 2021 / 2024 versions prior to July 2026 updates
- Microsoft Office Online Server versions prior to 16.0.10417.20175
Timeline
- 2026-07-14: disclosed: Initial publication of the CVE record.
- 2026-07-14: advisory: Microsoft released the security update guide for this vulnerability.