Executive brief
Microsoft Office Excel is a spreadsheet application widely used for data analysis and reporting in enterprises. A type confusion vulnerability allows attackers to execute arbitrary code on a user's computer by sending a specially crafted file over the network, potentially leading to system compromise and data theft without requiring any user interaction beyond opening the file.
Technical details
A type confusion vulnerability exists in Microsoft Office Excel's resource handling, where the application incorrectly validates or processes objects of incompatible types during parsing or execution. This vulnerability can be triggered by a specially crafted Excel file delivered over the network. The attack requires user interaction (opening the malicious file) but no authentication. Successful exploitation allows arbitrary code execution with the privileges of the user running Excel, potentially leading to complete system compromise. A patch is expected to be available through Microsoft's security updates.
Affected products
- Microsoft Office Excel
Timeline
- 2026-08-11: disclosed