PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-26257 Microsoft CVE debrief

CVE-2024-26257 is a high-severity remote code execution vulnerability in Microsoft Excel, published by NVD on 2024-04-09 and last modified on 2026-05-19. The vulnerability carries a CVSS 3.1 score of 7.8 (HIGH) with a vector of AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, indicating local attack vector, low attack complexity, no privileges required, but user interaction required, with high impacts to confidentiality, integrity, and availability. The weakness is associated with CWE-415 (Double Free) per Microsoft's advisory, though NVD lists it as NVD-CWE-noinfo. Affected products include Microsoft 365 Apps for Enterprise and Microsoft Office LTSC 2021 for macOS. The vulnerability requires user interaction, typically involving a victim opening a maliciously crafted Excel file. Microsoft has released security updates to address this issue. Organizations should apply the available patches from Microsoft and exercise caution with Excel files from untrusted sources.

Vendor
Microsoft
Product
Microsoft 365 Apps for Enterprise
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2024-04-09
Original CVE updated
2026-05-19
Advisory published
2024-04-09
Advisory updated
2026-05-19

Who should care

Organizations using Microsoft Excel as part of Microsoft 365 Apps for Enterprise or Office LTSC 2021 for macOS should prioritize patching. Security teams responsible for endpoint protection, email security, and user awareness training should address this vulnerability. MacOS environments running Office LTSC 2021 are specifically affected and require attention.

Technical summary

CVE-2024-26257 is a remote code execution vulnerability in Microsoft Excel triggered by user interaction with a malicious file. The vulnerability involves a double-free memory corruption condition (CWE-415) that can lead to arbitrary code execution in the context of the current user. The attack requires local access in the sense that the victim must open a file, but the code execution occurs with the privileges of the user running Excel. Affected platforms include Microsoft 365 Apps for Enterprise and Office LTSC 2021 for macOS. The high CVSS score reflects significant impact potential across confidentiality, integrity, and availability dimensions.

Defensive priority

high

Recommended defensive actions

  • Apply Microsoft security updates for affected Microsoft 365 Apps and Office LTSC 2021 installations as detailed in the vendor advisory
  • Implement email filtering and attachment scanning to detect potentially malicious Excel files
  • Educate users on the risks of opening Excel attachments from untrusted or unexpected sources
  • Consider enabling Microsoft Office protected view or application guard for documents from the internet
  • Monitor for anomalous Excel process behavior that may indicate exploitation attempts

Evidence notes

CVSS vector and scoring derived from NVD source data. CWE-415 attribution from Microsoft MSRC advisory. Affected product list from CPE criteria in NVD record.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-26257 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-26257

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-26257 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-26257

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.