Executive brief
Microsoft Office Excel is a widely-used spreadsheet application in corporate environments. A heap buffer overflow vulnerability allows an attacker with local access to execute arbitrary code with the privileges of the user running Excel, potentially leading to data theft, system compromise, or further attack propagation.
Technical details
A heap-based buffer overflow exists in Microsoft Office Excel's memory handling logic. The vulnerability is triggered when processing specially crafted input, allowing an attacker to write beyond allocated buffer boundaries. Exploitation requires local access and user interaction (opening a malicious file). A successful exploit grants arbitrary code execution in the context of the affected user, enabling full system compromise depending on user privileges.
Affected products
- Microsoft Office Excel
Timeline
- 2026-08-11: disclosed