Junglewise Threat Intelligence

CVE-2026-81958: Microsoft Office Excel information disclosure via uninitialized resource

CVE-2026-81958 · Severity: medium · CVSS 5.5 · Published 2026-09-08

Executive brief

Microsoft Office Excel, a widely used spreadsheet application, contains a vulnerability where uninitialized memory resources can be exploited by a local attacker to read sensitive information from the system. An attacker with local access to a machine running Excel could potentially extract confidential data that was previously stored in memory, compromising data confidentiality.

Technical details

The vulnerability is a use-of-uninitialized-resource flaw in Microsoft Office Excel that permits local information disclosure. The root cause involves inadequate initialization of memory resources, allowing an attacker with local access to read uninitialized buffer contents. The attack vector is local, requiring the attacker to have direct access to the affected system. An attacker can exploit this to read sensitive data from memory, potentially including cached information from previous operations. The vulnerability is not known to be exploited in the wild, and patches are expected to be available from Microsoft.

Affected products

  • Microsoft Office Excel <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats