CVE-2026-20955
vulnerability analysis and mitigation

Overview

CVE-2026-20955 is an untrusted pointer dereference vulnerability in Microsoft Office Excel that allows an unauthorized attacker to execute code locally. Disclosed on January 13, 2026, as part of Microsoft's January 2026 Patch Tuesday, it affects Microsoft Office 2019, Office LTSC 2021 and 2024 (Windows and macOS), Microsoft 365 Apps for Enterprise, and Office Online Server (prior to version 16.0.10417.20083). It carries a CVSS v3.1 base score of 7.8 (High), assigned by Microsoft (Microsoft MSRC, Feedly).

Technical details

The vulnerability is classified as CWE-822 (Untrusted Pointer Dereference), meaning the application dereferences a pointer that is derived from untrusted input — in this case, data within a maliciously crafted Excel file. An attacker exploits this by convincing a user to open a specially crafted Excel document, which triggers the unsafe pointer dereference and leads to arbitrary code execution in the context of the current user. The attack vector is local (the file must be opened on the target system), requires no special privileges, but does require user interaction. No public proof-of-concept or detailed technical write-up has been identified at this time (Microsoft MSRC, Feedly).

Impact

Successful exploitation results in arbitrary code execution on the victim's system with high impact to confidentiality, integrity, and availability. An attacker who exploits this vulnerability can gain full control of the affected system, potentially enabling data theft, installation of malware, lateral movement within a network, or complete system compromise. The scope is limited to the affected host (unchanged scope), but the breadth of affected products — including widely deployed Microsoft 365 Apps for Enterprise — means the potential attack surface is significant (Feedly).

Exploitation steps

  1. Craft a malicious Excel file: An attacker creates a specially crafted .xlsx or .xls file that contains data designed to trigger an untrusted pointer dereference within Excel's parsing logic.
  2. Deliver the file to the target: The attacker distributes the malicious file via phishing email, malicious download link, or other social engineering methods targeting users of affected Office versions.
  3. User opens the file: The victim opens the malicious Excel file using a vulnerable version of Microsoft Office Excel (Office 2019, LTSC 2021/2024, or Microsoft 365 Apps for Enterprise).
  4. Trigger the vulnerability: Excel processes the malicious file content, causing it to dereference an untrusted pointer, leading to memory corruption.
  5. Achieve code execution: The memory corruption is leveraged to redirect execution flow, allowing the attacker to execute arbitrary code in the context of the logged-in user, potentially enabling persistence, data exfiltration, or further lateral movement (Microsoft MSRC, Feedly).

Indicators of compromise

  • Process: Unusual child processes spawned by EXCEL.EXE (e.g., cmd.exe, powershell.exe, wscript.exe, mshta.exe) shortly after opening an Excel file.
  • File System: Unexpected files dropped in %TEMP%, %APPDATA%, or Office startup folders following Excel activity; new or modified files with suspicious extensions in user-writable directories.
  • Network: Outbound network connections initiated by EXCEL.EXE to unknown or suspicious external IP addresses or domains, particularly after opening an untrusted document.
  • Logs: Windows Event Logs showing application crashes or faulting module entries related to EXCEL.EXE; crash dump files (.dmp) generated in %LOCALAPPDATA%\CrashDumps associated with Excel.
  • Registry: New autorun entries or scheduled tasks created under the context of the user account running Excel, potentially indicating post-exploitation persistence.

Mitigation and workarounds

Microsoft released patches for all affected products on January 13, 2026, including Office Online Server (fixed in version 16.0.10417.20083), Microsoft 365 Apps for Enterprise, Office 2019, Office LTSC 2021 and 2024 (Windows and macOS), and Office LTSC for Mac 2021/2024 (fixed in version 16.105.26011018). Organizations should immediately apply the January 2026 security updates via Windows Update, Microsoft Update Catalog, or their patch management solution. As a temporary workaround, administrators can restrict execution of Excel files from untrusted sources, enforce Protected View settings, disable macros, and educate users to avoid opening Excel attachments from unknown senders (Microsoft MSRC, Feedly).

Community reactions

The vulnerability was covered as part of broader January 2026 Patch Tuesday roundups by multiple security outlets including BleepingComputer, Cisco Talos, Zero Day Initiative, Qualys, CrowdStrike, and Sophos, though CVE-2026-20955 was not individually highlighted as a top-priority flaw given the absence of active exploitation (Talos Blog, ZDI, Qualys Blog). Community attention during January 2026 Patch Tuesday was primarily focused on the three zero-day vulnerabilities patched that month, with CVE-2026-20955 receiving standard coverage as a High-severity Excel flaw.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management