Executive brief
Microsoft Office Excel contains a heap-based buffer overflow vulnerability that could allow an attacker to execute arbitrary code on a user's computer when a specially crafted Excel file is opened. This represents a direct threat to data security and system integrity for organizations relying on Excel for sensitive business operations.
Technical details
A heap-based buffer overflow exists in Microsoft Office Excel's document parsing logic. The vulnerability is triggered when Excel processes a specially crafted spreadsheet file, allowing an attacker to overwrite heap memory and achieve arbitrary code execution with the privileges of the user running Excel. The attack requires user interaction (opening a malicious file) and operates via the local attack vector. There is no indication of active exploitation in the wild at this time, though the high CVSS score reflects the severity of code execution capability.
Affected products
- Microsoft Office Excel
Timeline
- 2026-09-08: disclosed