Executive brief
A security vulnerability exists in Microsoft Excel that could allow an attacker to take control of a user's computer. To exploit this, an attacker would typically need to trick a user into opening a specially crafted malicious Excel file. Successful exploitation could lead to the unauthorized installation of programs, data theft, or full system compromise.
Technical details
A stack-based buffer overflow (CWE-121) exists in Microsoft Office Excel due to improper validation of user-supplied data when parsing Excel files. The vulnerability is triggered when a user opens a specially crafted file, leading to memory corruption. An attacker can exploit this to execute arbitrary code in the context of the current user. The attack vector is local, requiring user interaction (UI:R) to open the malicious document. Microsoft has released security updates for various versions of Office, including Excel 2016, 2019, LTSC 2021/2024, and Microsoft 365 Apps.
Affected products
- Microsoft Excel 2016 16.0.0.0 to 16.0.5561.1001
- Microsoft Office 2019 19.0.0 to latest security release
- Microsoft Office LTSC 2021 16.0.1 to latest security release
- Microsoft Office LTSC 2024 16.0.0 to latest security release
- Microsoft 365 Apps for Enterprise 16.0.1 to latest security release
- Microsoft Office 365 for Mac 1.0.0 to 16.111.26071215
- Microsoft Office Online Server 16.0.0.0 to 16.0.10417.20175
Timeline
- 2026-07-14: disclosed: Initial publication of CVE-2026-55141 by Microsoft.