Executive brief
Microsoft Office Excel contains a type confusion vulnerability that allows an attacker to disclose information on a local system. The vulnerability could be exploited through a specially crafted Excel file, potentially exposing sensitive data stored on the affected computer without requiring special privileges.
Technical details
The vulnerability is a type confusion flaw in Microsoft Office Excel's resource access logic. An attacker can craft a malicious Excel file that triggers incorrect type handling during resource access, leading to information disclosure. The attack is local in nature and requires a user to open a specially crafted file. No authentication is required to trigger the vulnerability. An attacker can leverage this to read sensitive information from the affected system's memory or disk.
Affected products
- Microsoft Office Excel
Timeline
- 2026-09-08: disclosed