Executive brief
Microsoft Excel, a widely used spreadsheet application, is vulnerable to a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker would typically need to trick a user into opening a specially crafted malicious file. If successful, the attacker could gain the same permissions as the user, potentially leading to data theft, unauthorized software installation, or disruption of business operations.
Technical details
A heap-based buffer overflow (CWE-122) exists in Microsoft Office Excel across multiple versions, including Microsoft 365 Apps and LTSC editions for both Windows and Mac. The vulnerability is triggered when the application processes a specially crafted file, leading to memory corruption. While the attack vector is classified as local, it requires user interaction, typically involving the victim opening a malicious spreadsheet. Successful exploitation allows for arbitrary code execution in the context of the current user. Microsoft has released security updates to address this issue; users should refer to the Microsoft Security Update Guide for specific patch versions.
Affected products
- Microsoft Microsoft 365 Apps for Enterprise 16.0.1 to latest security release
- Microsoft Microsoft Office 365 for Mac 1.0.0 to 16.111.26071215
- Microsoft Microsoft Office LTSC 2021 16.0.1 to latest security release
- Microsoft Microsoft Office LTSC 2024 16.0.0 to latest security release
- Microsoft Microsoft Office LTSC for Mac 2021 16.0.1 to 16.111.26071215
- Microsoft Microsoft Office LTSC for Mac 2024 16.0.0 to 16.111.26071215
Timeline
- 2026-07-14: disclosed: Initial publication by Microsoft and NVD
- 2026-07-14: advisory: Microsoft Security Update Guide published