Executive brief
Microsoft Office Excel is a widely used spreadsheet application in enterprise and personal computing. An integer overflow vulnerability in Excel allows an attacker with local access to execute arbitrary code with the privileges of the user running Excel, potentially compromising sensitive financial data, formulas, and other confidential spreadsheet information.
Technical details
An integer overflow or wraparound vulnerability exists in Microsoft Office Excel's internal processing logic. The vulnerability requires local access to the affected system and typically involves opening a specially crafted Excel file that triggers the integer overflow condition. When exploited, an attacker can bypass memory protections and execute arbitrary code with the same privileges as the user running Excel. The vulnerability is not known to be actively exploited in the wild. Microsoft has issued security patches to address this issue.
Affected products
- Microsoft Office Excel
Timeline
- 2026-09-08: disclosed