
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20955 is an untrusted pointer dereference vulnerability in Microsoft Office Excel that allows an unauthorized attacker to execute code locally. Disclosed on January 13, 2026, as part of Microsoft's January 2026 Patch Tuesday, it affects Microsoft Office 2019, Office LTSC 2021 and 2024 (Windows and macOS), Microsoft 365 Apps for Enterprise, and Office Online Server (prior to version 16.0.10417.20083). It carries a CVSS v3.1 base score of 7.8 (High), assigned by Microsoft (Microsoft MSRC, Feedly).
The vulnerability is classified as CWE-822 (Untrusted Pointer Dereference), meaning the application dereferences a pointer that is derived from untrusted input — in this case, data within a maliciously crafted Excel file. An attacker exploits this by convincing a user to open a specially crafted Excel document, which triggers the unsafe pointer dereference and leads to arbitrary code execution in the context of the current user. The attack vector is local (the file must be opened on the target system), requires no special privileges, but does require user interaction. No public proof-of-concept or detailed technical write-up has been identified at this time (Microsoft MSRC, Feedly).
Successful exploitation results in arbitrary code execution on the victim's system with high impact to confidentiality, integrity, and availability. An attacker who exploits this vulnerability can gain full control of the affected system, potentially enabling data theft, installation of malware, lateral movement within a network, or complete system compromise. The scope is limited to the affected host (unchanged scope), but the breadth of affected products — including widely deployed Microsoft 365 Apps for Enterprise — means the potential attack surface is significant (Feedly).
.xlsx or .xls file that contains data designed to trigger an untrusted pointer dereference within Excel's parsing logic.EXCEL.EXE (e.g., cmd.exe, powershell.exe, wscript.exe, mshta.exe) shortly after opening an Excel file.%TEMP%, %APPDATA%, or Office startup folders following Excel activity; new or modified files with suspicious extensions in user-writable directories.EXCEL.EXE to unknown or suspicious external IP addresses or domains, particularly after opening an untrusted document.EXCEL.EXE; crash dump files (.dmp) generated in %LOCALAPPDATA%\CrashDumps associated with Excel.Microsoft released patches for all affected products on January 13, 2026, including Office Online Server (fixed in version 16.0.10417.20083), Microsoft 365 Apps for Enterprise, Office 2019, Office LTSC 2021 and 2024 (Windows and macOS), and Office LTSC for Mac 2021/2024 (fixed in version 16.105.26011018). Organizations should immediately apply the January 2026 security updates via Windows Update, Microsoft Update Catalog, or their patch management solution. As a temporary workaround, administrators can restrict execution of Excel files from untrusted sources, enforce Protected View settings, disable macros, and educate users to avoid opening Excel attachments from unknown senders (Microsoft MSRC, Feedly).
The vulnerability was covered as part of broader January 2026 Patch Tuesday roundups by multiple security outlets including BleepingComputer, Cisco Talos, Zero Day Initiative, Qualys, CrowdStrike, and Sophos, though CVE-2026-20955 was not individually highlighted as a top-priority flaw given the absence of active exploitation (Talos Blog, ZDI, Qualys Blog). Community attention during January 2026 Patch Tuesday was primarily focused on the three zero-day vulnerabilities patched that month, with CVE-2026-20955 receiving standard coverage as a High-severity Excel flaw.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."