Executive brief
Microsoft Office Excel is a widely-used spreadsheet application for data analysis and reporting. A stack-based buffer overflow vulnerability allows an attacker to execute arbitrary code on a user's computer by crafting a malicious Excel file. Exploitation requires the user to open the malicious file locally, but successful exploitation could lead to complete system compromise.
Technical details
A stack-based buffer overflow exists in Microsoft Office Excel, triggered during the parsing or processing of specially crafted spreadsheet files. The vulnerability does not require network access or authentication; it is triggered by local file interaction. An attacker can craft a malicious Excel document that, when opened by a user, overflows a stack buffer to achieve arbitrary code execution with the privileges of the user running Excel. Patches are expected to be available through Microsoft's security update channels.
Affected products
- Microsoft Office Excel
Timeline
- 2026-09-08: disclosed