Description
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Published: 2026-07-14
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out-of-bounds read flaw in Microsoft Office Excel permits a local attacker to read data beyond the intended buffer, potentially exposing sensitive memory contents or files accessed by Excel. This weakness, identified as CWE-125, allows disclosure of confidential information without granting code execution or system takeover capabilities.

Affected Systems

Affected products include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Microsoft Office Online Server. No specific version ranges are given, so the entire product lines listed are potentially impacted.

Risk and Exploitability

The CVSS score of 6.1 indicates medium severity, while an EPSS score of less than 1% suggests a low likelihood of exploitation today. The vulnerability is not currently in the CISA KEV catalog. Exploitation requires local access to the target system and a crafted workbook or document; the description does not indicate a remote exploitation path. Consequently, the threat is limited to users who can run Excel files on the affected machine, and the risk primarily involves confidential data exposure rather than remote code execution.

Generated by OpenCVE AI on July 31, 2026 at 09:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft security update for the affected Excel and Office products via the Microsoft Update Guide, which patches the out‑of‑bounds read flaw (CWE‑125).
  • Enforce strict bounds checks when parsing workbook data—implement or enable validation to ensure all array and memory accesses stay within legitimate limits, thereby mitigating the CWE‑125 vulnerability.
  • Restrict the sources of opened workbooks to trusted locations and enable Excel’s safe mode or macro disabling policies to reduce the chance of encountering malformed files that could trigger the buffer over‑read.

Generated by OpenCVE AI on July 31, 2026 at 09:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 16 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft office Online Server
Vendors & Products Microsoft office Online Server

Tue, 14 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Title Microsoft Excel Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft 365 Apps
Microsoft excel 2016
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
Weaknesses CWE-125
CPEs cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:excel_2016:*:*:*:*:*:*:x86:*
cpe:2.3:a:microsoft:office_2019:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_2021:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_2021:*:*:*:*:ltsc:*:*:*
cpe:2.3:a:microsoft:office_2024:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_365:*:*:*:*:*:macos:*:*
cpe:2.3:a:microsoft:office_macos_2021:*:*:*:*:*:long_term_servicing_channel:*:*
cpe:2.3:a:microsoft:office_macos_2024:*:*:*:*:*:long_term_servicing_channel:*:*
Vendors & Products Microsoft
Microsoft 365 Apps
Microsoft excel 2016
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft 365 Apps Excel 2016 Office 2019 Office 2021 Office 2024 Office 365 Office Macos 2021 Office Macos 2024 Office Online Server
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:53:29.734Z

Reserved: 2026-06-16T14:10:05.868Z

Link: CVE-2026-54988

cve-icon Vulnrichment

Updated: 2026-07-14T17:48:58.976Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T09:30:05Z

Weaknesses