Executive brief
Microsoft Office Excel is a widely-used spreadsheet application relied upon by businesses for financial analysis, reporting, and data management. A heap-based buffer overflow vulnerability allows an attacker with local access to execute arbitrary code with the privileges of the user running Excel, potentially leading to data theft, system compromise, or lateral movement within a corporate network.
Technical details
This vulnerability is a heap-based buffer overflow in Microsoft Office Excel that occurs when the application processes malformed input, resulting in out-of-bounds memory writes. An attacker with local access can exploit this flaw by crafting a specially formatted Excel file or input that triggers the overflow. Successful exploitation allows arbitrary code execution in the context of the logged-in user. The vulnerability requires local access and user interaction (opening a malicious file). Microsoft has released patches to address this issue.
Affected products
- Microsoft Office Excel <UNKNOWN>
Timeline
- 2026-08-11: disclosed