Executive brief
Microsoft Office Excel contains a use of uninitialized resource vulnerability that allows a local, unauthorized attacker to read sensitive information from memory. An attacker with local access to a system running Excel could exploit this flaw to access confidential data, such as passwords or other sensitive business information stored in memory during Excel operations.
Technical details
This vulnerability is a use-of-uninitialized-resource flaw in Microsoft Office Excel where uninitialized memory is accessed, potentially exposing sensitive data to a local attacker. The attack vector is local, meaning an attacker must have access to the affected system. No network access or elevated privileges are required to trigger the disclosure. An attacker can read uninitialized memory regions to extract sensitive information. A patch is available; organizations should apply the security update released by Microsoft.
Affected products
- Microsoft Office Excel
Timeline
- 2026-09-08: disclosed