Executive brief
Microsoft Excel is a widely used spreadsheet application for financial analysis, reporting, and data manipulation. A numeric truncation error in Excel allows an attacker to execute arbitrary code on a user's computer when they open a malicious spreadsheet, potentially leading to data theft, system compromise, or malware installation.
Technical details
A numeric truncation error in Microsoft Excel's formula parsing or calculation engine fails to properly validate or handle numeric values, leading to a buffer overflow or out-of-bounds memory access. The vulnerability requires user interaction—an attacker must craft a malicious Excel file and trick a user into opening it. Upon opening the file, the numeric truncation flaw is triggered, allowing the attacker to execute arbitrary code with the privileges of the user running Excel. The vulnerability is classified as high severity with a CVSS score of 7.8, and patches are expected to be available from Microsoft.
Affected products
- Microsoft Office Excel
Timeline
- 2026-08-11: disclosed