Executive brief
Microsoft Office Excel is a widely-used spreadsheet application in corporate environments. This vulnerability allows an attacker with local access to the system to read sensitive information that should not be accessible, potentially exposing confidential business data or system configuration details.
Technical details
This vulnerability is an information disclosure flaw in Microsoft Office Excel that exposes sensitive system information to an unauthorized control sphere. The attack requires local access to the affected system. An attacker can exploit this to read sensitive data that should be protected. The vulnerability has a CVSS score of 5.5 (medium severity) and has not been reported as exploited in the wild as of the advisory publication date.
Affected products
- Microsoft Office Excel
Timeline
- 2026-09-08: disclosed