Executive brief
Microsoft Office Excel contains an out-of-bounds write vulnerability that allows an attacker to execute arbitrary code on a user's computer. An attacker could exploit this by crafting a malicious Excel file; when opened, the vulnerability could lead to complete system compromise, including data theft, installation of malware, or ransomware deployment.
Technical details
The vulnerability is an out-of-bounds write condition in Microsoft Office Excel's file parsing logic. The root cause involves insufficient bounds checking when processing certain Excel file structures, allowing an attacker to write data beyond allocated memory boundaries. Exploitation requires user interaction (opening a malicious Excel file) and no authentication. A successful exploit grants the attacker code execution at the privilege level of the user running Excel, potentially leading to full system compromise depending on user privileges.
Affected products
- Microsoft Office Excel
Timeline
- 2026-08-11: disclosed