Executive brief
Microsoft Office Excel is a widely-used spreadsheet application deployed across enterprises and consumers. This vulnerability allows an attacker with local access to read sensitive information from memory that should not be accessible, potentially exposing confidential data such as formulae, cell values, or other information contained in spreadsheets.
Technical details
An out-of-bounds read vulnerability exists in Microsoft Office Excel's memory handling routines. The vulnerability requires local access to the affected system and does not require authentication to trigger. An attacker can craft a malicious Office file that, when opened by a user, causes Excel to read from uninitialized or protected memory regions, disclosing information that may include previously-used data or memory contents. The attack is a classic information disclosure scenario with a reported CVSS score of 5.5 (medium severity).
Affected products
- Microsoft Office Excel
Timeline
- 2026-08-11: disclosed