CVE-2024-49026

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Nov 12, 2024
Updated: Nov 16, 2024
CWE ID 77

Summary

CVE-2024-49026 is a newly disclosed remote code execution vulnerability affecting Microsoft Excel. Attackers can exploit this flaw by tricking victims into opening a specially crafted Excel file, which could lead to the execution of arbitrary code. Successful exploitation allows attackers to gain the same privileges as the user running the software, potentially leading to significant data theft or system compromise. Microsoft is actively working on a patch to mitigate this issue, but until then, users are advised to exercise caution when opening unexpected Excel files.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Office
  • Microsoft Office Online Server

Affected Vendors

  • Microsoft