CVE-2026-50678
Analyzed Analyzed - Analysis Complete

Heap-based Buffer Overflow in Microsoft Office Excel

Vulnerability report for CVE-2026-50678, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-15

Assigner: Microsoft Corporation

Description

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-15
Generated
2026-08-03
AI Q&A
2026-07-14
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 14 associated CPEs
Vendor Product Version / Range
microsoft 365_apps *
microsoft 365_apps *
microsoft excel 2016
microsoft excel 2016
microsoft office_2019 *
microsoft office_2019 *
microsoft microsoft_365 *
microsoft office_2021 *
microsoft office_2021 *
microsoft office_2021 *
microsoft office_2024 *
microsoft office_2024 *
microsoft office_2024 *
microsoft office_online_server to 16.0.10417.20175 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-122 A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-50678 is a heap-based buffer overflow vulnerability in Microsoft Office Excel. This flaw allows an unauthorized attacker to disclose information locally on the affected system.

A heap-based buffer overflow occurs when a program writes more data to a buffer than it can hold, corrupting or overwriting adjacent memory. In this case, the vulnerability in Excel could be exploited to access sensitive information stored in memory.

  • The CVSS v3.1 base score is 6.6, indicating a medium severity level.
  • The attack vector is local (AV:L), meaning the attacker must have access to the system.
  • The vulnerability requires user interaction (UI:R), such as opening a malicious file.
  • The impact includes low confidentiality (C:L), low integrity (I:L), and high availability (A:H) effects.
Detection Guidance

The provided context does not include specific detection methods or commands for identifying the presence of CVE-2026-50678 on a network or system. Detection typically involves checking for vulnerable versions of Microsoft Office Excel or using security tools that can identify heap-based buffer overflow vulnerabilities in installed software.

For accurate detection, refer to Microsoft's official guidance or use their security tools, such as Microsoft Defender for Office 365 or the Microsoft Safety Scanner, which may include checks for this vulnerability.

Impact Analysis

If you use Microsoft Office Excel, this vulnerability could impact you in several ways:

  • An attacker could exploit this flaw to access sensitive information stored in memory on your system, such as passwords, documents, or other confidential data.
  • The vulnerability could lead to local information disclosure, meaning an attacker with access to your system could retrieve data without your knowledge.
  • Exploitation requires user interaction, such as opening a specially crafted Excel file, which could be delivered via email or other means.
  • While the confidentiality and integrity impacts are low, the availability impact is high, meaning an attacker could potentially crash the application or cause it to become unresponsive.
Compliance Impact

This vulnerability could have implications for compliance with standards and regulations, depending on the context of its exploitation:

  • GDPR: If the disclosed information includes personal data of EU citizens, this vulnerability could lead to a breach of GDPR. Organizations must ensure the confidentiality and security of personal data, and failure to patch or mitigate this vulnerability could result in non-compliance.
  • HIPAA: For organizations handling protected health information (PHI), this vulnerability could lead to unauthorized access to sensitive patient data. HIPAA requires safeguards to protect PHI, and exploitation of this flaw could violate those requirements.
  • Other standards: Depending on the industry, this vulnerability could also impact compliance with frameworks like PCI DSS (if financial data is exposed) or ISO 27001 (if it leads to a breach of information security controls).

Organizations should assess the risk posed by this vulnerability and apply patches or mitigations to maintain compliance with relevant regulations.

Mitigation Strategies

To mitigate CVE-2026-50678, apply the latest security updates provided by Microsoft for Microsoft Office Excel. The following steps are recommended:

  • Check for and install any available patches or updates for Microsoft Office Excel through Windows Update or the Microsoft Update Catalog.
  • If an update is not immediately available, consider restricting access to Excel files from untrusted sources until a patch is applied.
  • Monitor Microsoft's security advisories for additional guidance or workarounds related to this vulnerability.

For detailed mitigation steps, refer to the official Microsoft security update guide linked in Resource 1.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-50678. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart