Executive brief
Microsoft Office Excel contains an out-of-bounds read vulnerability that allows an attacker with local access to read sensitive information from the application's memory. An attacker could exploit this to disclose confidential data such as spreadsheet contents, credentials, or other sensitive information stored in memory.
Technical details
The vulnerability is an out-of-bounds read in Microsoft Office Excel that permits disclosure of information. The flaw allows an attacker with local access to the system to read memory beyond intended boundaries, potentially exposing sensitive data. Exploitation requires local access to the affected system. The out-of-bounds read can be triggered to leak arbitrary memory contents from the Excel process.
Affected products
- Microsoft Office Excel <UNKNOWN>
Timeline
- 2026-09-08: disclosed