Executive brief
Microsoft Office Excel contains an out-of-bounds read vulnerability that allows an attacker to access and disclose sensitive information from local system memory. This vulnerability requires local access to exploit, limiting exposure to users on the same physical machine or those with local file access. An attacker could exploit this to leak confidential data such as customer information, trade secrets, or other sensitive materials stored in memory.
Technical details
This vulnerability is a classic out-of-bounds read flaw in Microsoft Office Excel's memory handling. The vulnerability allows an attacker with local access to craft a malicious Excel file or trigger improper memory access that reads beyond allocated buffer boundaries, potentially exposing sensitive data from adjacent memory regions. The attack vector is local and does not require elevated privileges or network access, though it may require the user to open a specially crafted file. An attacker can disclose information currently resident in process memory. Patches or mitigations are expected to be available through Microsoft's regular security update process.
Affected products
- Microsoft Office Excel <UNKNOWN>
Timeline
- 2026-09-08: disclosed