Executive brief
Microsoft Excel is a spreadsheet application used across businesses for data analysis and reporting. A heap-based buffer overflow vulnerability allows an attacker with local access to execute arbitrary code on the affected system, potentially leading to data theft, system compromise, or further lateral movement within the network.
Technical details
A heap-based buffer overflow exists in Microsoft Excel's memory handling during file processing. An attacker with local system access can exploit this vulnerability by crafting a malicious Excel file that, when opened by a user or processed by the application, overflows a heap buffer and executes arbitrary code with the privileges of the user running Excel. No network-based exploitation is possible; physical access or local file placement is required. The vulnerability has not been observed in active exploitation in the wild as of the publication date.
Affected products
- Microsoft Excel
Timeline
- 2026-08-11: disclosed