Executive brief
Microsoft Office Excel contains a vulnerability in its pointer handling logic that allows a local attacker to execute arbitrary code with the privileges of the user running Excel. An attacker could exploit this by crafting a malicious document that, when opened, triggers unsafe memory access and leads to code execution on the victim's system.
Technical details
The vulnerability is a classic untrusted pointer dereference in Microsoft Office Excel's document processing code. An attacker can craft a specially crafted Excel file that causes the application to dereference a malicious or corrupted pointer, leading to arbitrary code execution. The attack requires local code execution capability and user interaction (opening a malicious file). The vulnerability has a CVSS score of 7.8, indicating high severity. A patch is expected to be available through Microsoft's security updates.
Affected products
- Microsoft Office Excel
Timeline
- 2026-08-11: disclosed