Executive brief
Microsoft Office Excel contains a memory corruption vulnerability that allows local attackers to execute arbitrary code on a user's system when a malicious spreadsheet file is opened. This could enable complete compromise of user data, installation of malware, or lateral movement within a corporate environment.
Technical details
A double free vulnerability exists in Microsoft Office Excel's memory management, allowing attackers to trigger code execution through a crafted spreadsheet file. The vulnerability requires local code execution capability and user interaction (opening a malicious Excel file). An attacker can exploit this to achieve arbitrary code execution with the privileges of the user running Excel, potentially leading to full system compromise.
Affected products
- Microsoft Office Excel <UNKNOWN>
Timeline
- 2026-09-08: disclosed