PT-2026-2756 · Microsoft · Office Excel

Jmini

+1

·

Published

2026-01-13

·

Updated

2026-01-19

·

CVE-2026-20957

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Office Excel (affected versions not specified)
Description An integer underflow condition exists in Microsoft Office Excel that could allow an unauthorized attacker to execute code locally. The issue is due to an integer underflow, also known as a wrap or wraparound.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Integer Underflow

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2026-00401
CVE-2026-20957

Affected Products

Office Excel