Executive brief
Microsoft Office Excel contains a vulnerability where uninitialized memory is not properly cleared, allowing a local attacker to read sensitive information from the application's memory. An attacker with local access to a computer running Excel could potentially recover confidential data such as formula contents, cached calculations, or other sensitive spreadsheet information that was previously processed.
Technical details
The vulnerability is a use-of-uninitialized-resource defect in Microsoft Office Excel where memory allocated for internal operations is not properly initialized or cleared before use. This allows an authenticated local attacker to read remnants of sensitive data from application memory. The attack vector is local, requiring access to the affected system; however, no special user interaction or elevated privileges are explicitly required beyond basic access to Excel. An attacker can disclose information that may include previously processed spreadsheet data or internal application state.
Affected products
- Microsoft Office Excel
Timeline
- 2026-08-11: disclosed