Executive brief
A security vulnerability has been identified in Microsoft Excel, the widely used spreadsheet application. An attacker could exploit this flaw by tricking a user into opening a specially crafted file, potentially allowing the attacker to take control of the user's computer. This could lead to the theft of sensitive data, unauthorized changes to files, or the installation of malicious software.
Technical details
A stack-based buffer overflow vulnerability (CWE-121) exists in Microsoft Excel due to improper input validation (CWE-20) when processing specially crafted files. The attack vector is local, requiring a user to open a malicious document (User Interaction: Required). Successful exploitation allows an attacker to execute arbitrary code in the context of the current user, potentially leading to full system compromise. Affected products include various versions of Microsoft Office, Excel 2016, and Office Online Server. Microsoft has released security updates to address this issue across the affected product suites.
Affected products
- Microsoft Excel 2016 < 16.0.5561.1001
- Microsoft Office 2019 All versions
- Microsoft Office LTSC 2021 All versions
- Microsoft Office LTSC 2024 All versions
- Microsoft 365 Apps for Enterprise All versions
- Microsoft Office 365 for Mac < 16.111.26071215
- Microsoft Office Online Server < 16.0.10417.20175
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory