Executive brief
Microsoft Office Excel contains a heap-based buffer overflow vulnerability that allows a locally-authenticated attacker to execute arbitrary code on an affected system. This could enable an attacker to gain full control of a user's computer, steal sensitive data, or distribute malware within an organization.
Technical details
The vulnerability is a heap-based buffer overflow in Microsoft Office Excel that permits an attacker with local access and the ability to open a specially-crafted Excel file to achieve arbitrary code execution. The flaw resides in memory management within Excel's file parsing logic. An attacker would need to trick a user into opening a malicious Excel document, after which the overflow condition could be triggered to corrupt heap memory and redirect execution to attacker-controlled code. Patches are expected to be available through Microsoft's regular security updates.
Affected products
- Microsoft Office Excel
Timeline
- 2026-08-11: disclosed