Microsoft Office Excel in Microsoft has an out-of-bounds read that can disclose local information

What is CVE-2026-85875?

CVE-2026-85875 is a vulnerability classified as Out-of-bounds Read, affecting Microsoft 365 Apps for Enterprise (affected versions: 16.0.1 – < 16.0.20326.20138), Microsoft Excel 2016 (affected versions: 16.0.0.0 – < 16.0.5569.1003), Microsoft Office 2016 (affected versions: 16.0.0 – < 16.0.5569.1003), and 6 more products. This vulnerability is rated Medium, with a CVSS score of 5.5. Current sources do not report this vulnerability as exploited.

Verify to continue the analysis

A short verification protects the vulnerability source and prevents automated AI abuse.

Overview

Original source data

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Affected products and scope

The affected data lists the following branches. The Windows branches are recorded for 32-bit Systems and x64-based Systems:

  • Microsoft 365 Apps for Enterprise: affected at 16.0.1 and versions less than 16.0.20326.20138.
  • Microsoft Excel 2016: affected at 16.0.0.0 and versions less than 16.0.5569.1003.
  • Microsoft Office 2016: affected at 16.0.0 and versions less than 16.0.5569.1003.
  • Microsoft Office 2019: affected at 19.0.0 and versions less than 16.0.10417.20207.
  • Microsoft Office LTSC 2021: affected at 16.0.1 and versions less than 16.0.14334.20906.
  • Microsoft Office LTSC 2024: affected at 16.0.0 and versions less than 16.0.17932.20976.
  • Microsoft Office 365 for Mac: recorded as affected with version -; no numeric boundary is supplied.
  • Microsoft Office LTSC for Mac 2021: recorded as affected with version -; no numeric boundary is supplied.
  • Microsoft Office LTSC for Mac 2024: recorded as affected with version -; no numeric boundary is supplied.

These are the affected boundaries recorded in the source data. The Mac status must not be inferred from the numeric boundaries for Windows branches.

Technical details

The flaw is classified as CWE-125, which occurs when code reads beyond the intended bounds of a memory region. Here, the affected component is Microsoft Office Excel, and the described outcome is local information disclosure. The available evidence does not identify the triggering workbook or content, parser, code path, memory object, or exact type of data that may be disclosed. Exploitation is recorded as local, requires no privileges, has low complexity, and requires user interaction. The recorded scope is unchanged and the described impact is limited to confidentiality; no implementation detail establishes remote reachability or code execution.

Exploitability

  • Reachability: Exploitation is described as local rather than remotely reachable over a network.
  • Conditions: No privileges are required, complexity is low, and user interaction is required.
  • Exploitation status: The supplied record marks public_exploit as false. The returned CISA ADP data records exploitation as none and automatable as no.
  • This status does not prove that exploitation is impossible; it indicates only that no exploitation evidence is recorded in the available data.

Technical impact

The confirmed technical outcome is possible local information disclosure caused by an out-of-bounds read in Excel. A successful attack could expose sensitive data accessible to the Excel process, but the type and extent of disclosure remain unspecified. Exploitation requires local access and user interaction, while no privileges are required, so exposure is concentrated on endpoints running an affected Office branch. The record does not confirm data modification, service disruption, privilege escalation, or code execution.

Business impact

Successful exploitation could expose information processed by Excel or present in memory accessible to the affected component, but the record does not specify the data that would be disclosed. This creates a confidentiality risk on endpoints handling sensitive spreadsheets or other data, although no specific disclosure scenario is established. The record does not establish integrity, availability, or code-execution consequences. Operationally, organizations need branch-specific update and verification processes for both Windows and Mac Office deployments.

Remediation

  1. Apply Microsoft's security update for each affected branch and verify that each Windows installation is no longer within the affected range listed in affected_summary.
  2. Use the branch-specific boundaries during validation: Microsoft 365 Apps for Enterprise below 16.0.20326.20138, Excel 2016 and Office 2016 below 16.0.5569.1003, Office 2019 below 16.0.10417.20207, Office LTSC 2021 below 16.0.14334.20906, and Office LTSC 2024 below 16.0.17932.20976 are recorded as affected.
  3. For Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024, the record provides no numeric version boundary. Apply the Microsoft update for the relevant Mac branch and verify its build against Microsoft's update guidance.
  4. Do not infer a single fixed release for all branches from the boundary of another product. In particular, do not use the Windows thresholds to conclude that a Mac product is fixed.
  5. No workaround or specific mitigation is provided in the record. Do not treat disabling an unconfirmed feature or changing configuration as a confirmed fix.
  6. After updating, rescan endpoint inventory, retain the actual product and build evidence, and separately remediate systems that remain within an affected range.

Detection

  • Inventory Microsoft Office Excel and the Microsoft Office products listed in affected_summary across both Windows and Mac deployments.
  • Record the complete product name and installed build from software-management data or the Office About screen, then compare each installation with the applicable version boundary in affected_summary.
  • For Mac products, do not infer safety from the numeric Windows boundaries because the source data provides no numeric boundary for the Mac entries.
  • The available evidence does not identify a specific log event, IOC, or telemetry pattern for this flaw. General endpoint monitoring may be used as a precaution, but the absence of an unusual event does not prove that a system is safe.
  • After updating, repeat the inventory check and retain the installed build evidence to confirm that each branch has left the affected range.
Sources (5)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan
CyStack VulnScan dashboard