Microsoft Office Excel Untrusted Pointer Dereference Information Disclosure Vulnerability

Vulnerability

A vulnerability allowing information disclosure has been identified in Microsoft Office Excel. This issue arises from an untrusted pointer dereference, which could enable an unauthorized attacker to read small portions of heap memory over a network. The vulnerability affects multiple Microsoft Office products, including Excel, and requires user interaction to exploit.

Impact

Exploitation of this vulnerability could lead to unauthorized information disclosure, allowing an attacker to read portions of the application's heap memory.

Remediation

Users can download the security update for this vulnerability through the Microsoft Update Catalog. For Microsoft Office LTSC for Mac 2024, the update is available via the Mac App Store. Instructions for downloading the security update for Microsoft 365 Apps for Enterprise are also available on the Microsoft Office Update page.

Added: Nov 11, 2025, 7:12 PM
Updated: Nov 11, 2025, 7:12 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
2.5
exploitability
4.4
remediation
7.7
relevance
1.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.