ZeroHour

CVE-2026-81388

mass

Stack Buffer Overflow in Microsoft Excel Allows Local Code Execution

CVSS 3.1
7.8 high
EPSS
<1%p38
Published
()
Modified
AI analysis

Microsoft Excel is affected by a stack-based buffer overflow (CWE-121) that an unauthorized local attacker can leverage to execute arbitrary code. The CVSS vector indicates the attack requires user interaction and no privileges or special conditions, consistent with an attacker convincing a user to open a specially crafted Excel workbook on a vulnerable machine. Successful exploitation would yield code execution in the context of the local user, with high impact on confidentiality, integrity, and availability of the affected system. Affected products include Excel within Microsoft 365/Microsoft 365 Apps and the perpetual Office 2016, 2019, 2021, and 2024 releases. As of this analysis there is no known exploitation, no public proof-of-concept, and the flaw is not listed in CISA's KEV; EPSS estimates roughly a 0.5% chance of exploitation within 30 days.

What to do: Apply the Microsoft security update for CVE-2026-81388 across all affected Office channels (Microsoft 365 Apps and Office 2016/2019/2021/2024), using the fixed builds listed in Microsoft's advisory since specific version numbers are not provided here. Until patched, treat unsolicited Excel workbooks and spreadsheets from untrusted sources as suspect, since exploitation requires user interaction. There is no evidence of active exploitation, so patching on your normal monthly cycle is defensible for most environments, with faster action for high-risk users or shared workstations handling untrusted files.

Affected
microsoft excel
microsoft 365 apps
microsoft 365
microsoft office 2016
microsoft office 2019
microsoft office 2021
microsoft office 2024
Estimated exposure
masshundreds of millions of Office/Excel installations worldwide — Excel is a core component of Microsoft 365 and every perpetual Office release from 2016 through 2024, whose combined enterprise and consumer desktop installed base runs to hundreds of millions of seats, though actual exploitability depends…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Vendors
microsoft
Products
365 apps, excel, microsoft 365, office 2016, office 2019, office 2021, office 2024
Weakness
CWE-121
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.