Executive brief
Microsoft Office Excel is a widely used spreadsheet application used by organizations for financial analysis, data management, and reporting. An out-of-bounds read vulnerability in Excel could allow an attacker with local access to execute arbitrary code, potentially compromising sensitive business data and spreadsheets.
Technical details
This vulnerability is an out-of-bounds read in Microsoft Office Excel that can lead to local code execution. The vulnerability requires local access to the affected system and likely requires user interaction (opening a malicious Excel file). An attacker could craft a specially formed Excel file that, when opened, triggers the out-of-bounds read and potentially leads to arbitrary code execution with the privileges of the user running Excel. Patches are expected to be available through Microsoft's security updates.
Affected products
- Microsoft Office Excel
Timeline
- 2026-08-11: disclosed