Executive brief
Microsoft Office Excel is a widely-used spreadsheet application employed across organizations for data analysis and financial modeling. A heap-based buffer overflow vulnerability allows a local attacker to execute arbitrary code on a user's system, potentially leading to data theft, malware installation, or system compromise if a user is tricked into opening a malicious spreadsheet.
Technical details
A heap-based buffer overflow exists in Microsoft Office Excel, triggered by improper bounds checking in the application's memory handling. The vulnerability requires local access and likely involves opening a specially-crafted Excel file (.xls, .xlsx, or similar). An attacker can exploit this memory corruption to overwrite heap structures and achieve arbitrary code execution with the privileges of the logged-in user. Microsoft has released patches to address this vulnerability.
Affected products
- Microsoft Office Excel <UNKNOWN>
Timeline
- 2026-08-11: disclosed