Executive brief
Microsoft Office Excel is a widely used spreadsheet application in enterprise and personal computing environments. A heap-based buffer overflow vulnerability in Excel allows local attackers to execute arbitrary code with the privileges of the user running the application, potentially leading to data theft, malware installation, or system compromise.
Technical details
A heap-based buffer overflow exists in Microsoft Office Excel that allows local code execution. The vulnerability is triggered by processing specially crafted Excel files, requiring the user to open a malicious document. The buffer overflow occurs in heap memory, enabling an attacker to overwrite adjacent memory structures and achieve arbitrary code execution in the context of the Excel process. No network vector is involved; exploitation requires local access and user interaction to open a crafted file. Patches from Microsoft Security Response Center are available.
Affected products
- Microsoft Office Excel <UNKNOWN>
Timeline
- 2026-09-08: disclosed