Junglewise Threat Intelligence

CVE-2026-68797: Microsoft Office Excel out-of-bounds read in local information disclosure

CVE-2026-68797 · Severity: medium · CVSS 5.5 · Published 2026-08-11

Technologies: Microsoft Office Excel. Vendors: Microsoft.

Executive brief

Microsoft Office Excel contains an out-of-bounds read vulnerability that allows an attacker to access sensitive information on a user's computer. An attacker who tricks a user into opening a specially crafted Excel file can read portions of the system's memory, potentially exposing passwords, cryptographic keys, or other confidential data stored by other applications.

Technical details

The vulnerability is an out-of-bounds read in Microsoft Office Excel, a memory safety issue in the spreadsheet application's file parsing logic. The attack requires local access and user interaction—specifically, the victim must open a malicious Excel file. When processed, the vulnerable code reads memory beyond allocated buffer boundaries, allowing an attacker to disclose arbitrary data from the target process or adjacent memory regions. This is a local information disclosure vulnerability with no network attack vector. A patch is likely available through Microsoft's security update channels.

Affected products

  • Microsoft Office Excel <UNKNOWN>

Timeline

  • 2026-08-11: disclosed

References

Related threats