Impact
This vulnerability, identified as CVE-2026-81393, permits an attacker with local access to perform an out‑of‑bounds read in Microsoft Office Excel. The flaw enables the malicious party to read memory that should be inaccessible, leading to the accidental disclosure of sensitive data that may reside in the memory space of the application. The primary impact is the inadvertent exposure of confidential information stored in Excel or other Office documents, while the attack does not grant code execution or modify data.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. All of these Windows and macOS versions are vulnerable to the information disclosure flaw.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity, and the EPSS score is not available at this time. The vulnerability is not listed in the CISA KEV catalog, implying no known widespread exploitation. Attackers must have local access to the system and the ability to interact with Excel; no network‑based exploitation is described. The risk is primarily the potential unintended exposure of user data rather than privilege escalation or remote compromise.
OpenCVE Enrichment