Executive brief
Microsoft Excel is a widely-used spreadsheet application relied upon by organizations worldwide for data analysis and reporting. An out-of-bounds read vulnerability in Excel's parsing logic could allow an attacker to execute code locally on a victim's computer if they open a malicious spreadsheet file, potentially leading to data theft, system compromise, or lateral movement within a corporate network.
Technical details
The vulnerability is an out-of-bounds read flaw in Microsoft Excel's file parsing mechanism, likely triggered when processing a specially crafted spreadsheet. The vulnerability requires local code execution and user interaction (opening a malicious file), and is not remotely exploitable over the network. An attacker can achieve arbitrary code execution in the context of the user running Excel. The CVSS v3.1 base score is 7.8 (high severity), though it has not been observed exploited in the wild as of the advisory publication date.
Affected products
- Microsoft Excel
Timeline
- 2026-08-11: disclosed