Executive brief
Microsoft Office Excel contains a buffer over-read vulnerability that allows an attacker to disclose sensitive information from the affected system. An attacker can exploit this flaw by sending a specially crafted Excel file over the network, potentially exposing confidential data without requiring user authentication or interaction beyond opening the file.
Technical details
A buffer over-read vulnerability exists in Microsoft Office Excel's file parsing logic. The vulnerability stems from improper bounds checking when processing specially crafted Excel documents, allowing an attacker to read memory beyond allocated buffer boundaries. The attack vector is network-based and can be triggered when a user opens a malicious Excel file. An attacker can leverage this vulnerability to leak sensitive information from the application's memory, such as cached data or secrets. While no public exploits have been reported in the wild as of the advisory date, patches are available from Microsoft.
Affected products
- Microsoft Office Excel
Timeline
- 2026-09-08: disclosed