CVE-2026-55899
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: secure@microsoft.com (Secondary)
Description
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Affected (14)
Products: Microsoft: 365 Apps, Excel, Microsoft 365, Office 2019, Office 2021, Office 2024, Office Online Server
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| Version 2016 | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| Before 16.0.10417.20175 |
Related CWEs
CWE-121
Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
CWE-20
Improper Input Validation
The product receives input or data, but it does
not validate or incorrectly validates that the input has the
properties that are required to process the data safely and
correctly.
References (1)
Source: secure@microsoft.com
PatchVendor Advisory
Timeline
No history available yet.