Executive brief
Microsoft Office Excel is a widely used spreadsheet application in corporate environments. This vulnerability allows a local attacker with file access to execute arbitrary code on a user's computer by crafting a malicious Excel file, potentially leading to data theft, malware installation, or system compromise.
Technical details
A heap-based buffer overflow exists in Microsoft Office Excel's file parsing logic. The vulnerability is triggered when processing specially crafted Excel files and allows an attacker to overwrite heap memory and achieve code execution. The attack requires local access and user interaction (opening a malicious file). No network vector is available. Patches are expected from Microsoft's security updates.
Affected products
- Microsoft Office Excel <UNKNOWN>
Timeline
- 2026-09-08: disclosed