Executive brief
Microsoft Excel contains an out-of-bounds read vulnerability that allows an attacker to disclose sensitive information from affected systems over the network. An attacker can exploit this flaw to extract data from Excel spreadsheets or memory without requiring special credentials or user interaction. This could lead to exposure of confidential business data, customer information, or other sensitive content stored in or processed by Excel.
Technical details
An out-of-bounds read vulnerability exists in Microsoft Excel's data parsing or processing logic. The vulnerability allows an attacker to read memory beyond intended boundaries, potentially exposing sensitive information such as private keys, credentials, or file contents. The flaw is triggered when processing a specially crafted Excel file sent over the network, with no authentication or user interaction beyond opening the malicious document. An attacker can leverage this to extract confidential data from the affected system. Microsoft has released a security update to address this vulnerability.
Affected products
- Microsoft Excel
Timeline
- 2026-09-08: disclosed