Executive brief
Microsoft Office Excel is a widely-used spreadsheet application used by organizations for financial analysis, data management, and business reporting. A heap-based buffer overflow vulnerability allows an attacker to execute malicious code on a user's computer when a specially crafted Excel file is opened, potentially leading to data theft, malware installation, or system compromise.
Technical details
A heap-based buffer overflow exists in Microsoft Office Excel's file parsing logic. The vulnerability is triggered when processing a specially crafted Excel file, allowing an attacker to overflow a heap buffer and overwrite adjacent memory. The attack requires user interaction (opening a malicious file) and results in local code execution with the privileges of the user running Excel. No network connectivity is required. The vulnerability has been assigned CVE-2026-81947 with a CVSS score of 7.8.
Affected products
- Microsoft Office Excel
Timeline
- 2026-09-08: disclosed