Sceawere

Vulnerability Detail

CVE-2026-70318UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Microsoft Office Excel Information Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.5
Creation Date
7h ago
Vendor
Microsoft
Product
Microsoft 365 Apps for Enterprise
Attack Type
CWE-20: Improper Input Validation
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.5",
  "pubDate": "2026-08-11T17:19:09.320Z",
  "pubdate": "2026-08-11T17:19:09.320Z",
  "executiveSummary": "This vulnerability is an improper input validation flaw residing within Microsoft Office Excel. The primary security impact of this vulnerability is the unauthorized local disclosure of sensitive information, potentially exposing confidential data to an unauthorized threat actor.\nThe affected product is Microsoft Office Excel. The risk implications are moderate to high depending on the sensitivity of the data residing on the target system and the attacker's ability to access the local environment.\nAttacker capabilities are strictly constrained to local access requirements, implying that the adversary must already possess a foothold on the target machine or the ability to deliver and execute a specially crafted file locally.\nExploitation requirements include the victim opening a maliciously crafted file designed to trigger the improper input validation routine within the application parsing engine. No remote network vector is inherently described, framing this primarily as a local attack vector.\nSuccessful exploitation allows an unauthorized local user to bypass security boundaries intended to restrict access to local system information, leading to unauthorized data leakage.",
  "technicalDetails": "The root cause of the vulnerability stems from improper input validation within Microsoft Office Excel when parsing specific file structures or data objects. The application fails to adequately sanitize, bounds-check, or validate input parameters during the document parsing lifecycle.\nThe vulnerable component resides within the core file-parsing and data-rendering subsystems of Microsoft Office Excel, which handle internal structural representations of spreadsheet documents.\nRegarding authentication and privilege requirements, the attack does not inherently require elevated privileges to execute the initial phase, but it does require the attacker or an unsuspecting victim to execute the application locally with a specially crafted payload. The local exposure vector indicates that the attacker must operate within the local security context of the target system.\nThe step-by-step attack flow begins when an unauthorized attacker constructs a malformed Microsoft Office Excel file engineered to exploit the input validation weakness. The attacker delivers this file to the target system via local means, removable media, or social engineering. Upon delivery, the victim opens the malicious spreadsheet file using Microsoft Office Excel.\nAs Excel parses the malformed structures within the file, the lack of proper input validation causes the application to incorrectly process memory or local file references. Instead of rejecting the invalid input, the parsing engine proceeds to evaluate the crafted parameters, resulting in the unintended reading or exposure of local data structures.\nThe payload behavior focuses on extracting or reflecting local information back into a context accessible to the unauthorized attacker. The post-exploitation impact is characterized by local information disclosure, where sensitive memory contents, configuration details, or user data accessible to the application context are divulged.\nBecause the vulnerability is localized to input validation flaws during file parsing, it does not directly facilitate remote code execution based on the provided parameters, but it successfully compromises confidentiality by leaking local information."
}
CVE-2026-70318: Microsoft Office Excel Information Disclosure (MEDIUM Severity, CVSS: 5.5) - Sceawere