Executive brief
Microsoft Office Excel contains a memory access vulnerability that can allow a local attacker to read sensitive information from the application's memory. This could expose confidential data such as spreadsheet contents, cached credentials, or other information processed by Excel without requiring any special user interaction or prior authentication.
Technical details
An out-of-bounds read vulnerability exists in Microsoft Office Excel's memory handling. The vulnerability allows a local attacker to read data beyond the allocated buffer boundaries in the application's memory space, potentially disclosing sensitive information. The vulnerability requires local access to the system where Excel is running. No patch availability information is provided in the advisory text; refer to Microsoft Security Response Center for patch status and remediation guidance.
Affected products
- Microsoft Office Excel
Timeline
- 2026-09-08: disclosed