Executive brief
Microsoft Office Excel contains an out-of-bounds memory read vulnerability that allows an attacker to access and disclose sensitive information stored in memory. The vulnerability requires local access to the system and could enable an attacker to read confidential data such as passwords, encryption keys, or other sensitive content from affected user systems.
Technical details
An out-of-bounds read vulnerability exists in Microsoft Office Excel's memory handling routines. The vulnerability occurs when Excel attempts to read data beyond the allocated bounds of a memory buffer, potentially exposing adjacent memory contents to an attacker. This is a local attack that requires the attacker to execute code or interact with a malicious file on the target system. Successful exploitation allows disclosure of sensitive information stored in the process memory of Excel.
Affected products
- Microsoft Office Excel
Timeline
- 2026-09-08: disclosed