Executive brief
A security vulnerability has been identified in Microsoft Excel that could allow an attacker to run malicious code on a user's computer. This typically occurs if a user is tricked into opening a specially crafted Excel file. If exploited, an attacker could gain the same permissions as the local user, potentially leading to data theft, unauthorized system changes, or the installation of malware.
Technical details
A vulnerability classified as an untrusted pointer dereference (CWE-822) exists in Microsoft Excel. The flaw is triggered when the application processes a specially crafted file containing malicious pointer data that the application fails to properly validate before dereferencing. An attacker can exploit this by convincing a user to open a malicious spreadsheet, leading to arbitrary code execution in the context of the current user. The vulnerability affects multiple versions of Microsoft Office across Windows and macOS, including Office 2016, 2019, LTSC 2021/2024, and Microsoft 365 Apps. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Excel 2016 < 16.0.5561.1001
- Microsoft Office 2019 All versions
- Microsoft Office LTSC 2021 All versions
- Microsoft Office LTSC 2024 All versions
- Microsoft Microsoft 365 Apps for Enterprise All versions
- Microsoft Office Online Server < 16.0.10417.20175
- Microsoft Office for Mac (365, LTSC 2021, LTSC 2024) < 16.111.26071215
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory