Microsoft Excel Type Confusion Vulnerability Leading to Remote Code Execution

Vulnerability

A type confusion vulnerability has been identified in Microsoft Office Excel, allowing an unauthorized attacker to execute code locally. This issue arises from the access of a resource using an incompatible type, creating a scenario where an attacker could potentially manipulate the execution flow.

Impact

Exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.

Remediation

Users can download the security update for this vulnerability through the Microsoft Update Catalog. Security update details can be found in the Microsoft Knowledge Base articles 5002794 and 5002797.

Added: Oct 14, 2025, 6:23 PM
Updated: Oct 14, 2025, 8:50 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
10.0
exploitability
3.0
remediation
7.7
relevance
0.7
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.