Executive brief
Microsoft Office Excel is a spreadsheet application used by millions of organizations for data analysis and reporting. A heap-based buffer overflow vulnerability could allow an attacker with local access to execute arbitrary code with the privileges of the logged-in user, potentially compromising sensitive financial data, trade secrets, or enabling further system compromise.
Technical details
This is a heap-based buffer overflow vulnerability in Microsoft Office Excel that allows local code execution. The vulnerability is triggered through the processing of specially crafted Excel files or data within the application. No authentication is required beyond having local access to the system; the attack vector is local. An attacker can achieve arbitrary code execution in the context of the user running Excel. A patch should be available from Microsoft's Security Response Center.
Affected products
- Microsoft Office Excel
Timeline
- 2026-09-08: disclosed