Executive brief
Microsoft Office Excel contains a heap-based buffer overflow vulnerability that could allow an attacker with local access to execute arbitrary code on a user's computer. This could enable theft of sensitive documents, unauthorized modifications to spreadsheets, or installation of malware if an attacker tricks a user into opening a malicious Excel file.
Technical details
A heap-based buffer overflow vulnerability exists in Microsoft Office Excel's file parsing logic. The vulnerability is triggered when Excel processes a specially crafted spreadsheet file that causes improper bounds checking in heap memory allocation. An attacker must convince a user to open a malicious Excel file; the overflow then executes arbitrary code with the privileges of the Excel process. No network attack vector is available; exploitation requires local file access and user interaction. A patch is expected to be available from Microsoft Security Response Center.
Affected products
- Microsoft Office Excel
Timeline
- 2026-09-08: disclosed