Junglewise Threat Intelligence

CVE-2026-68795: Microsoft Office Excel stack-based buffer overflow

CVE-2026-68795 · Severity: high · CVSS 7.8 · Published 2026-08-11

Technologies: Microsoft Office Excel. Vendors: Microsoft.

Executive brief

Microsoft Office Excel contains a stack-based buffer overflow vulnerability that allows a local attacker to execute arbitrary code on an affected system. Exploitation requires the attacker to have local access and typically involves opening a specially crafted Excel file, potentially compromising sensitive business data or enabling lateral movement within a corporate network.

Technical details

A stack-based buffer overflow exists in Microsoft Office Excel's file parsing logic. The vulnerability is triggered when processing specially crafted Excel files that contain malformed data structures, causing a buffer overrun on the stack. An attacker with local system access can exploit this by tricking a user into opening a malicious spreadsheet file, leading to arbitrary code execution in the context of the Excel process. The vulnerability is classified as high severity with a CVSS score of 7.8.

Affected products

  • Microsoft Office Excel

Timeline

  • 2026-08-11: disclosed

References

Related threats