Executive brief
A security vulnerability exists in Microsoft Excel, the widely used spreadsheet application. An attacker could exploit this flaw to gain unauthorized access to sensitive information on a user's computer. To be successful, an attacker would typically need to trick a user into opening a specially crafted Excel file.
Technical details
An untrusted pointer dereference vulnerability (CWE-822) exists in multiple versions of Microsoft Excel and Office products. The flaw is triggered when the application processes a malformed file, leading to an out-of-bounds memory access. An attacker can exploit this by convincing a user to open a malicious document, which could result in the disclosure of sensitive memory contents. This is a local attack requiring user interaction, and while it does not allow for direct code execution, it can be used to bypass security mitigations like ASLR. Microsoft has released security updates to address this issue across affected platforms including Windows and macOS.
Affected products
- Microsoft Microsoft 365 Apps for Enterprise versions prior to July 2026 updates
- Microsoft Microsoft Excel 2016 versions prior to 16.0.5561.1001
- Microsoft Microsoft Office 2019 versions prior to July 2026 updates
- Microsoft Microsoft Office 365 for Mac versions prior to 16.111.26071215
- Microsoft Microsoft Office LTSC 2021 versions prior to July 2026 updates
- Microsoft Microsoft Office LTSC 2024 versions prior to July 2026 updates
- Microsoft Microsoft Office LTSC for Mac 2021 versions prior to 16.111.26071215
- Microsoft Microsoft Office LTSC for Mac 2024 versions prior to 16.111.26071215
- Microsoft Office Online Server versions prior to 16.0.10417.20175
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory