Executive brief
Microsoft Office Excel contains a type confusion vulnerability that allows an attacker to execute arbitrary code locally on a user's computer. An attacker could exploit this by crafting a malicious Excel file that, when opened by a user, triggers the vulnerability and executes code with the privileges of the affected user.
Technical details
This vulnerability is a type confusion issue in Microsoft Office Excel's resource access handling, classified as CWE-17 (Access of Resource using Incompatible Type). The vulnerability allows local code execution when a specially crafted Excel document is opened. The attack requires user interaction (opening a malicious file) but does not require authentication or network access. Exploitation could allow an attacker to execute arbitrary code in the context of the user running Excel. A fix is expected from Microsoft's security updates.
Affected products
- Microsoft Office Excel
Timeline
- 2026-08-11: disclosed