CVE-2026-26144
Description
Improper neutralization of input during web page generation (cross-site scripting) in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
Risk Information
Base Score
4.7
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
EPSS Score
Exploitation Probability
0.093
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Microsoft Excel Remote Code Execution Vulnerability for Microsoft 365 Apps for Monthly Enterprise Channel for x64 2602 of version(19725.20170) | Windows |
| Microsoft Excel Remote Code Execution Vulnerability for Microsoft 365 Apps for Monthly Enterprise Channel for x86 version 2602 (19725.20170) | Windows |
| Microsoft Excel Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Monthly Enterprise Channel for x64 2602 of version(19725.20170) | Windows |
| Microsoft Excel Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Monthly Enterprise Channel for x86 version 2602 (19725.20170) | Windows |
| Microsoft Excel Remote Code Execution Vulnerability for Office 2019 for x64 1808 of volume version(10417.20108) | Windows |
| Microsoft Excel Remote Code Execution Vulnerability for Office 2019 for x86 1808 of volume version(10417.20108) | Windows |
| Microsoft Excel Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Current Channel for x64 2602 of version(19725.20172) | Windows |
| Microsoft Excel Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Current Channel for x86 2602 of version(19725.20172) | Windows |
| Microsoft Excel Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Current Channel for x64 2602 of version(19725.20172) | Windows |
| Microsoft Excel Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Current Channel for x86 2602 of version(19725.20172) | Windows |
| Microsoft Excel Remote Code Execution Vulnerability for Office 2021 for x64 2602 of Retail Version(19725.20172) | Windows |
| Microsoft Excel Remote Code Execution Vulnerability for Office 2021 for x86 2602 of Retail Version(19725.20172) | Windows |
| Microsoft Excel Remote Code Execution Vulnerability for Office 2024 for x86 2602 of Retail Version(19725.20172) | Windows |
| Microsoft Excel Remote Code Execution Vulnerability for Office 2024 for x64 2602 of Retail Version(19725.20172) | Windows |
| Microsoft Excel Remote Code Execution Vulnerability for Office 2021 for x64 2108 of volume version(14334.20570) | Windows |
| Microsoft Excel Remote Code Execution Vulnerability for Office 2021 for x86 2108 of volume version(14334.20570) | Windows |
| Microsoft Excel Remote Code Execution Vulnerability for Office 2024 for x64 2408 of volume version(17932.20700) | Windows |
| Microsoft Excel Remote Code Execution Vulnerability for Office 2024 for x86 2408 of volume version(17932.20700) | Windows |
| Microsoft Excel Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Semi Annual Channel for x64 2508 of version(19127.20570) | Windows |
| Microsoft Excel Remote Code Execution Vulnerability for Microsoft 365 Apps for Business Semi Annual Channel for x86 2508 of version(19127.20570) | Windows |
| Microsoft Excel Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Channel for x64 2508 of version(19127.20570) | Windows |
| Microsoft Excel Remote Code Execution Vulnerability for Microsoft 365 Apps for Enterprise Semi Annual Channel for x86 2508 of version(19127.20570) | Windows |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-43634 | Update for Microsoft 365 Apps for Monthly Enterprise Channel for x64 2602 of version(19725.20170) |
| PATCH-43636 | Update for Microsoft 365 Apps for Monthly Enterprise Channel for x86 version 2602 (19725.20170) |
| PATCH-43638 | Update for Microsoft 365 Apps for Business Monthly Enterprise Channel for x64 2602 of version(19725.20170) |
| PATCH-43640 | Update for Microsoft 365 Apps for Business Monthly Enterprise Channel for x86 version 2602 (19725.20170) |
| PATCH-43650 | Update for Office 2019 for x64 1808 of volume version(10417.20108) |
| PATCH-43652 | Update for Office 2019 for x86 1808 of volume version(10417.20108) |
| PATCH-43626 | Update for Microsoft 365 Apps for Business Current Channel for x64 2602 of version(19725.20172) |
| PATCH-43628 | Update for Microsoft 365 Apps for Business Current Channel for x86 2602 of version(19725.20172) |
| PATCH-43630 | Update for Microsoft 365 Apps for Enterprise Current Channel for x64 2602 of version(19725.20172) |
| PATCH-43632 | Update for Microsoft 365 Apps for Enterprise Current Channel for x86 2602 of version(19725.20172) |
| PATCH-43658 | Update for Office 2021 for x64 2602 of Retail Version(19725.20172) |
| PATCH-43660 | Update for Office 2021 for x86 2602 of Retail Version(19725.20172) |
| PATCH-43666 | Update for Office 2024 for x86 2602 of Retail Version(19725.20172) |
| PATCH-43668 | Update for Office 2024 for x64 2602 of Retail Version(19725.20172) |
| PATCH-43654 | Update for Office 2021 for x64 2108 of volume version(14334.20570) |
| PATCH-43656 | Update for Office 2021 for x86 2108 of volume version(14334.20570) |
| PATCH-43662 | Update for Office 2024 for x64 2408 of volume version(17932.20700) |
| PATCH-43664 | Update for Office 2024 for x86 2408 of volume version(17932.20700) |
| PATCH-43642 | Update for Microsoft 365 Apps for Business Semi Annual Channel for x64 2508 of version(19127.20570) |
| PATCH-43644 | Update for Microsoft 365 Apps for Business Semi Annual Channel for x86 2508 of version(19127.20570) |
| PATCH-43646 | Update for Microsoft 365 Apps for Enterprise Semi Annual Channel for x64 2508 of version(19127.20570) |
| PATCH-43648 | Update for Microsoft 365 Apps for Enterprise Semi Annual Channel for x86 2508 of version(19127.20570) |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234