Executive brief
Microsoft Office Excel is a widely used spreadsheet application deployed across organizations for data analysis and reporting. A heap-based buffer overflow vulnerability allows an attacker with local access to execute arbitrary code with the privileges of the user running Excel, potentially leading to data theft, system compromise, or lateral movement within a corporate network.
Technical details
A heap-based buffer overflow exists in Microsoft Office Excel's memory handling routines. The vulnerability occurs when Excel processes specially crafted or malformed spreadsheet data, causing a buffer on the heap to overflow and overwrite adjacent memory structures. Exploitation requires local access to the system and user interaction (opening a malicious spreadsheet file). Successful exploitation allows arbitrary code execution in the context of the user running Excel. A security patch is available from Microsoft.
Affected products
- Microsoft Office Excel <UNKNOWN>
Timeline
- 2026-08-11: disclosed