PT-2026-23860 · Xlnt · Xlnt

Oneafter

·

Publicado

2026-03-07

·

Atualizado

2026-03-10

·

CVE-2026-3664

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions xlnt versions up to 1.6.1
Description An issue exists in the xlnt library, specifically within the xlnt::detail::compound document::read directory function located in the source/detail/cryptography/compound document.cpp file. This relates to the Encrypted XLSX File Parser component and can lead to an out-of-bounds read condition. The issue is restricted to local execution and has been publicly disclosed.
Recommendations Apply patch 147 to resolve this issue.

Exploit

Correção

Buffer Overflow

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-3664

Produtos afetados

Xlnt