ZeroHour

CVE-2026-81389

mass

Heap Buffer Overflow in Microsoft Excel Enables Local Code Execution

CVSS 3.1
7.0 high
EPSS
<1%p29
Published
()
Modified
AI analysis

CVE-2026-81389 is a heap-based buffer overflow (CWE-122) in Microsoft Excel, affecting the Excel component within Microsoft 365 Apps, Microsoft 365, and the perpetual Office 2016, 2019, 2021, and 2024 releases. The CVSS score of 7.0 (high) reflects a local attack vector with high attack complexity and required user interaction, meaning an unauthorized attacker must typically persuade a user on the target machine to open a maliciously crafted spreadsheet for the overflow to occur. If successful, the attacker executes arbitrary code locally with the privileges of that user, with high impact on confidentiality, integrity, and availability. All users of the affected Excel/Office products are conceptually exposed, but current risk is rated low: there is no known in-the-wild exploitation, no public proof-of-concept, the CVE is not in CISA KEV, and EPSS assigns only a 0.4% probability of exploitation within 30 days.

What to do: Apply the Excel/Office security updates referenced in Microsoft's advisory for CVE-2026-81389 through Microsoft Update or the Microsoft Update Catalog as soon as they are published, since specific fixed version numbers are not included in the source data. Until patched, discourage opening spreadsheets from untrusted sources and prioritize endpoints where users routinely handle external files. Inventory your environment to identify installs of Office 2016/2019/2021/2024 and Microsoft 365 Apps and confirm they receive the update.

Affected
Microsoft 365 Apps
Microsoft Excel
Microsoft 365
Microsoft Office 2016
Microsoft Office 2019
Microsoft Office 2021
Microsoft Office 2024
Estimated exposure
masshundreds of millions of Office/Excel users (Microsoft 365 alone has roughly 400M+ paid seats) — Excel is bundled with nearly every Microsoft 365 and Office installation, whose global install base runs to hundreds of millions of users, though practical risk is tempered by the local, user-interaction-required attack vector.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Vendors
microsoft
Products
365 apps, excel, microsoft 365, office 2016, office 2019, office 2021, office 2024
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.