Executive brief
A security vulnerability exists in Microsoft Excel, the widely used spreadsheet application. An attacker could exploit this flaw by tricking a user into opening a specially crafted file, potentially allowing the attacker to take control of the user's computer. This could lead to the theft of sensitive data, installation of malicious software, or disruption of business operations.
Technical details
A heap-based buffer overflow vulnerability (CWE-122) exists in Microsoft Office Excel. The flaw is triggered when the application improperly handles objects in memory while processing a specially crafted file. An attacker can exploit this by convincing a user to open a malicious Excel document, leading to arbitrary code execution in the context of the current user. The attack vector is local, requiring user interaction (UI:R), and affects multiple versions of Office across Windows and macOS, as well as Office Online Server. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Microsoft 365 Apps for Enterprise >= 16.0.1
- Microsoft Microsoft Excel 2016 16.0.0.0 to 16.0.5561.1001
- Microsoft Microsoft Office 2019 >= 19.0.0
- Microsoft Microsoft Office 365 for Mac 1.0.0 to 16.111.26071215
- Microsoft Microsoft Office LTSC 2021 >= 16.0.1
- Microsoft Microsoft Office LTSC 2024 >= 16.0.0
- Microsoft Office Online Server 16.0.0.0 to 16.0.10417.20175
Timeline
- 2026-07-14: disclosed: Initial publication of the CVE record.
- 2026-07-14: advisory: Microsoft released security update details.