Executive brief
Microsoft Office Excel contains an out-of-bounds read vulnerability that allows an attacker to read memory beyond intended boundaries, potentially exposing sensitive information from the affected system. This vulnerability requires local access and can be exploited to retrieve data that should not be accessible, such as credentials or file contents.
Technical details
The vulnerability is an out-of-bounds read in Microsoft Office Excel that occurs when the application processes malformed input or specific file structures. The flaw resides in memory access bounds checking within Excel's parsing or processing logic. An attacker must have local access to the system and typically needs to interact with a specially crafted file or trigger specific conditions within Excel to exploit this issue. Successful exploitation allows disclosure of adjacent memory contents, which may include sensitive application data. A patch addressing this issue has been released by Microsoft.
Affected products
- Microsoft Office Excel affected versions not specified
Timeline
- 2026-08-11: disclosed