PatchSiren cyber security CVE debrief
CVE-2024-26257 Microsoft CVE debrief
CVE-2024-26257 is a high-severity remote code execution vulnerability in Microsoft Excel, published by NVD on 2024-04-09 and last modified on 2026-05-19. The vulnerability carries a CVSS 3.1 score of 7.8 (HIGH) with a vector of AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, indicating local attack vector, low attack complexity, no privileges required, but user interaction required, with high impacts to confidentiality, integrity, and availability. The weakness is associated with CWE-415 (Double Free) per Microsoft's advisory, though NVD lists it as NVD-CWE-noinfo. Affected products include Microsoft 365 Apps for Enterprise and Microsoft Office LTSC 2021 for macOS. The vulnerability requires user interaction, typically involving a victim opening a maliciously crafted Excel file. Microsoft has released security updates to address this issue. Organizations should apply the available patches from Microsoft and exercise caution with Excel files from untrusted sources.
- Vendor
- Microsoft
- Product
- Microsoft 365 Apps for Enterprise
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-04-09
- Original CVE updated
- 2026-05-19
- Advisory published
- 2024-04-09
- Advisory updated
- 2026-05-19
Who should care
Organizations using Microsoft Excel as part of Microsoft 365 Apps for Enterprise or Office LTSC 2021 for macOS should prioritize patching. Security teams responsible for endpoint protection, email security, and user awareness training should address this vulnerability. MacOS environments running Office LTSC 2021 are specifically affected and require attention.
Technical summary
CVE-2024-26257 is a remote code execution vulnerability in Microsoft Excel triggered by user interaction with a malicious file. The vulnerability involves a double-free memory corruption condition (CWE-415) that can lead to arbitrary code execution in the context of the current user. The attack requires local access in the sense that the victim must open a file, but the code execution occurs with the privileges of the user running Excel. Affected platforms include Microsoft 365 Apps for Enterprise and Office LTSC 2021 for macOS. The high CVSS score reflects significant impact potential across confidentiality, integrity, and availability dimensions.
Defensive priority
high
Recommended defensive actions
- Apply Microsoft security updates for affected Microsoft 365 Apps and Office LTSC 2021 installations as detailed in the vendor advisory
- Implement email filtering and attachment scanning to detect potentially malicious Excel files
- Educate users on the risks of opening Excel attachments from untrusted or unexpected sources
- Consider enabling Microsoft Office protected view or application guard for documents from the internet
- Monitor for anomalous Excel process behavior that may indicate exploitation attempts
Evidence notes
CVSS vector and scoring derived from NVD source data. CWE-415 attribution from Microsoft MSRC advisory. Affected product list from CPE criteria in NVD record.
Official resources
-
CVE-2024-26257 CVE record
CVE.org
-
CVE-2024-26257 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
2024-04-09