CNNVD-202601-2048 Information

CNNVD ID

CNNVD-202601-2048

CVE-2026-20949

  • CNNVD Published: 2026-01-13

Description (Chinese)

Microsoft Excel是美国微软(Microsoft)公司的一款Office套件中的电子表格处理软件。 Microsoft Excel存在访问控制错误漏洞。攻击者利用该漏洞可以绕过某些功能。以下产品和版本受到影响:Microsoft 365 Apps for Enterprise for 32-bit Systems,Microsoft 365 Apps for Enterprise for 64-bit Systems,Microsoft Office LTSC for Mac 2021,Microsoft Office LTSC 2021 for 64-bit editions,Microsoft Office LTSC 2021 for 32-bit editions,Microsoft Office LTSC 2024 for 32-bit editions,Microsoft Office LTSC 2024 for 64-bit editions,Microsoft Office LTSC for Mac 2024。

Description (English)

Microsoft Excel is a spreadsheet processing software in an Office package of Microsoft (USA). Microsoft Excel has a bug in access control. The attackers used that loophole to circumvent certain functions. The following products and versions have been affected: Microsoft 365 Apps for Enterprise 32-bit Systems, Microsoft 365 Apps for Enterprise 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit applications, Microsoft Office LTSC 2021 for 32-bit editions, Microsoft Office LTSC 2024 for 32-bit assessments, Microsoft Office LTSC 2024 for 32-bit editions, Microsoft Office Liechtenstein 2024 for 64-bit editions, Microsoft Office Liechtenstein 2024 for 64-bit edicts, Microsoft Office LtdSC for Mac 2024.

Hazard Level

Medium

Vulnerability Type

访问控制错误

Affected Vendor

微软

Published

2026-01-13

Last Modified

2026-02-24

References

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20949

Patch

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20949

Share on: