PT-2026-23859 · Xlnt · Xlnt

Oneafter

·

Publicado

2026-03-07

·

Atualizado

2026-03-10

·

CVE-2026-3663

CVSS v3.1

7.1

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions xlnt versions up to 1.6.1
Description A flaw exists within the xlnt library, specifically in the XLSX File Parser component. This issue resides in the xlnt::detail::compound document istreambuf::xsgetn function within the source/detail/cryptography/compound document.cpp file. A manipulation of the file can lead to an out-of-bounds read, and the exploit has been publicly disclosed. The issue is only exploitable with local access.
Recommendations Apply patch 147 to resolve this issue.

Exploit

Correção

Buffer Overflow

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-3663

Produtos afetados

Xlnt