Executive brief
Microsoft Office Excel contains a type confusion vulnerability that allows an attacker to execute arbitrary code on a user's computer by opening a maliciously crafted spreadsheet. This could result in complete system compromise, data theft, or installation of malware without requiring administrative privileges.
Technical details
A type confusion vulnerability exists in Microsoft Office Excel where the application incorrectly handles resource access with incompatible types, allowing memory corruption. An attacker can exploit this vulnerability by crafting a malicious Excel file that, when opened by a user, triggers the type confusion condition. The vulnerability requires user interaction (opening a file) and results in arbitrary code execution with the privileges of the user running Excel. No patch information is currently available in the provided advisory.
Affected products
- Microsoft Office Excel
Timeline
- 2026-08-11: disclosed