Junglewise Threat Intelligence

CVE-2026-55138: Microsoft Excel untrusted pointer dereference information disclosure

CVE-2026-55138 · Severity: medium · CVSS 5.5 · Published 2026-07-14

Technologies: Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2024, Microsoft Office 365 for Mac, Microsoft Excel 2016, Microsoft Office Online Server, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021, Microsoft Office 2019. Vendors: Microsoft.

Executive brief

A security vulnerability exists in Microsoft Excel, the widely used spreadsheet application. An attacker could exploit this flaw to gain unauthorized access to sensitive information on a user's computer. To be successful, an attacker would typically need to trick a user into opening a specially crafted Excel file.

Technical details

An untrusted pointer dereference vulnerability (CWE-822) exists in multiple versions of Microsoft Excel and Office products. The flaw is triggered when the application processes a malformed file, leading to an out-of-bounds memory access. An attacker can exploit this by convincing a user to open a malicious document, which could result in the disclosure of sensitive memory contents. This is a local attack requiring user interaction, and while it does not allow for direct code execution, it can be used to bypass security mitigations like ASLR. Microsoft has released security updates to address this issue across affected platforms including Windows and macOS.

Affected products

  • Microsoft Microsoft 365 Apps for Enterprise versions prior to July 2026 updates
  • Microsoft Microsoft Excel 2016 versions prior to 16.0.5561.1001
  • Microsoft Microsoft Office 2019 versions prior to July 2026 updates
  • Microsoft Microsoft Office 365 for Mac versions prior to 16.111.26071215
  • Microsoft Microsoft Office LTSC 2021 versions prior to July 2026 updates
  • Microsoft Microsoft Office LTSC 2024 versions prior to July 2026 updates
  • Microsoft Microsoft Office LTSC for Mac 2021 versions prior to 16.111.26071215
  • Microsoft Microsoft Office LTSC for Mac 2024 versions prior to 16.111.26071215
  • Microsoft Office Online Server versions prior to 16.0.10417.20175

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats