Home
HIGH: 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 16.0.1 (custom) before https://aka.ms/OfficeSecurityReleases
affected
16.0.0.0 (custom) before 16.0.5535.1000
affected
19.0.0 (custom) before https://aka.ms/OfficeSecurityReleases
affected
16.0.1 (custom) before https://aka.ms/OfficeSecurityReleases
affected
16.0.0 (custom) before https://aka.ms/OfficeSecurityReleases
affected
16.0.1 (custom) before 16.105.26011018
affected
16.0.0 (custom) before 16.105.26011018
affected
16.0.0.0 (custom) before 16.0.10417.20083
affected
Description
Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Problem types
CWE-191: Integer Underflow (Wrap or Wraparound)
CWE-122: Heap-based Buffer Overflow
Product status
References
msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20957 (Microsoft Excel Remote Code Execution Vulnerability)