Executive brief
Microsoft Office Excel contains a stack-based buffer overflow vulnerability that allows a local attacker to execute arbitrary code on an affected system. Exploitation requires the attacker to have local access and typically involves opening a specially crafted Excel file, potentially compromising sensitive business data or enabling lateral movement within a corporate network.
Technical details
A stack-based buffer overflow exists in Microsoft Office Excel's file parsing logic. The vulnerability is triggered when processing specially crafted Excel files that contain malformed data structures, causing a buffer overrun on the stack. An attacker with local system access can exploit this by tricking a user into opening a malicious spreadsheet file, leading to arbitrary code execution in the context of the Excel process. The vulnerability is classified as high severity with a CVSS score of 7.8.
Affected products
- Microsoft Office Excel
Timeline
- 2026-08-11: disclosed