Reference
Windows laptop displaying Microsoft Excel 2016 with security update notification in modern office environment
KB5002718Microsoft OfficeMicrosoft Office

KB5002718 — Security Update for Microsoft Excel 2016

KB5002718 is a security update released on March 10, 2026, that addresses multiple vulnerabilities in Microsoft Excel 2016, including remote code execution and information disclosure flaws affecting both 32-bit and 64-bit editions.

Emanuel DE ALMEIDAEmanuel DE ALMEIDA
11 Mar 202612 min read0 views

KB5002718 is a security update released on March 10, 2026, that addresses multiple vulnerabilities in Microsoft Excel 2016, including remote code execution and information disclosure flaws affecting both 32-bit and 64-bit editions.

Overview

KB5002718 is a March 2026 security update for Microsoft Excel 2016 that patches critical vulnerabilities including remote code execution and information disclosure flaws. This update applies to both 32-bit and 64-bit editions of Excel 2016 and is delivered through Microsoft Update.

Applies to

Microsoft Excel 2016 (32-bit edition)Microsoft Excel 2016 (64-bit edition)Windows 10Windows 11Windows Server 2016Windows Server 2019Windows Server 2022

Issue Description

Issue Description

This security update addresses several vulnerabilities in Microsoft Excel 2016 that could allow attackers to execute arbitrary code or access sensitive information:

  • Remote Code Execution: Specially crafted Excel files could allow an attacker to execute code in the context of the current user when opened
  • Information Disclosure: Malicious Excel documents could expose memory contents, potentially revealing sensitive data
  • Memory Corruption: Improper handling of objects in memory could lead to application crashes or code execution
  • Parsing Vulnerabilities: Malformed Excel file structures could trigger buffer overflows or other memory safety issues
Important: These vulnerabilities could be exploited through email attachments, web downloads, or network file shares containing malicious Excel files.

Root Cause

Root Cause

The vulnerabilities stem from improper input validation and memory management in Excel's file parsing engine. Specifically, the application fails to properly validate certain data structures within Excel files, leading to buffer overflows and memory corruption issues. Additionally, insufficient bounds checking when processing embedded objects and formulas creates opportunities for remote code execution attacks.

1

Fixes remote code execution vulnerability in Excel file parsing (CVE-2026-0847)

This update patches a critical remote code execution vulnerability in Excel's file parsing engine. The fix implements proper bounds checking and input validation when processing Excel file headers and embedded objects. This prevents attackers from exploiting malformed Excel files to execute arbitrary code on the target system.

Technical Details:

  • Enhanced validation of Excel file structure elements
  • Improved memory allocation and deallocation routines
  • Strengthened parsing of embedded OLE objects
  • Additional security checks for macro-enabled workbooks
2

Resolves information disclosure vulnerability in formula processing (CVE-2026-0848)

Addresses an information disclosure vulnerability where specially crafted formulas could cause Excel to read beyond allocated memory boundaries, potentially exposing sensitive data from other applications or system memory.

Technical Details:

  • Corrected memory boundary checks in formula evaluation engine
  • Enhanced validation of cell references and range operations
  • Improved handling of external data connections
  • Strengthened protection against memory disclosure attacks
3

Patches memory corruption issue in chart object handling (CVE-2026-0849)

Fixes a memory corruption vulnerability in Excel's chart rendering component that could be exploited through malicious chart objects embedded in Excel files. The vulnerability could lead to application crashes or potential code execution.

Technical Details:

  • Improved validation of chart data structures
  • Enhanced memory management for chart rendering operations
  • Corrected buffer size calculations for chart elements
  • Additional safety checks for chart data series processing
4

Strengthens security for external data connections and queries

Enhances security controls for external data connections, web queries, and database connections to prevent unauthorized data access and potential security bypasses through malicious connection strings.

Technical Details:

  • Improved validation of connection string parameters
  • Enhanced authentication checks for external data sources
  • Strengthened URL validation for web queries
  • Additional security warnings for potentially unsafe connections

Installation

Installation

KB5002718 is available through multiple installation methods:

Microsoft Update (Recommended)

The update is automatically delivered through Microsoft Update for systems with automatic updates enabled. Installation typically occurs during the next scheduled update cycle.

Microsoft Update Catalog

Manual download is available from the Microsoft Update Catalog for enterprise deployment:

  • File Size: Approximately 85 MB (32-bit), 95 MB (64-bit)
  • Restart Required: No (Excel restart recommended)
  • Installation Time: 5-10 minutes

Enterprise Deployment

System administrators can deploy this update through:

  • Windows Server Update Services (WSUS)
  • Microsoft System Center Configuration Manager (SCCM)
  • Microsoft Intune
  • Group Policy

Prerequisites

Before installing KB5002718, ensure the following requirements are met:

  • Microsoft Excel 2016 (32-bit or 64-bit edition) must be installed
  • Minimum 500 MB free disk space
  • Administrative privileges for installation
  • Close all Office applications before installation
Note: This update can be installed alongside other Office 2016 security updates without conflicts.

Known Issues

Known Issues

The following issues have been reported after installing KB5002718:

Installation Issues

  • Error 0x80070643: Installation may fail if Office applications are running. Close all Office programs and retry installation.
  • Error 0x80240017: Insufficient disk space. Ensure at least 500 MB free space is available on the system drive.

Post-Installation Issues

  • Slow Excel Startup: Some users may experience slightly longer Excel startup times due to enhanced security checks. This is expected behavior.
  • External Data Connection Prompts: Users may see additional security prompts when opening files with external data connections. This is an intended security enhancement.
  • Macro Security Warnings: Enhanced macro security may result in additional warning dialogs for macro-enabled workbooks.

Workarounds

  • For startup performance issues, disable unnecessary add-ins through File > Options > Add-ins
  • Configure trusted locations for frequently used files with external connections
  • Update macro security settings through File > Options > Trust Center if needed
Important: Do not disable security features to work around prompts, as this may expose systems to the vulnerabilities this update addresses.

Overview

KB5002718 is a critical security update for Microsoft Excel 2016 released on March 10, 2026. This update addresses multiple high-severity vulnerabilities that could allow remote code execution, information disclosure, and memory corruption attacks through specially crafted Excel files.

Affected Systems

This security update applies to the following Microsoft Excel 2016 editions:

ProductEditionArchitectureStatus
Microsoft Excel 2016Standard32-bitAffected
Microsoft Excel 2016Standard64-bitAffected
Microsoft Excel 2016Professional Plus32-bitAffected
Microsoft Excel 2016Professional Plus64-bitAffected

Security Vulnerabilities Addressed

This update resolves four critical security vulnerabilities:

CVE-2026-0847: Remote Code Execution Vulnerability

A remote code execution vulnerability exists in Microsoft Excel when the software fails to properly validate input. An attacker who successfully exploited this vulnerability could run arbitrary code in the context of the current user. Exploitation requires user interaction, typically opening a malicious Excel file.

CVE-2026-0848: Information Disclosure Vulnerability

An information disclosure vulnerability exists when Excel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user's system. Exploitation could occur through specially crafted formulas or external data connections.

CVE-2026-0849: Memory Corruption Vulnerability

A memory corruption vulnerability exists in Excel's chart rendering engine. An attacker could exploit this vulnerability by convincing a user to open a specially crafted file containing malicious chart objects, potentially leading to code execution or application crashes.

Enhanced Security for External Connections

This update also strengthens security controls for external data connections, web queries, and database connections to prevent potential security bypasses and unauthorized data access.

Installation Requirements

Before installing KB5002718, verify the following system requirements:

  • Operating System: Windows 10, Windows 11, Windows Server 2016, Windows Server 2019, or Windows Server 2022
  • Microsoft Excel 2016: Any edition (32-bit or 64-bit)
  • Disk Space: Minimum 500 MB free space
  • User Rights: Administrative privileges required for installation
  • Network: Internet connection for automatic updates

Deployment Methods

Automatic Updates

For most users, KB5002718 will be automatically downloaded and installed through Microsoft Update. The update is classified as Important and will be included in the regular update cycle.

Manual Installation

Enterprise administrators can manually deploy this update using:

  • Microsoft Update Catalog downloads
  • Windows Server Update Services (WSUS)
  • System Center Configuration Manager
  • Microsoft Intune for cloud-managed devices

Verification Commands

To verify successful installation, use the following PowerShell command:

Get-HotFix -Id KB5002718

Or check through Control Panel > Programs and Features > View installed updates.

Security Impact

Installing KB5002718 provides the following security improvements:

  • Prevents Remote Code Execution: Blocks exploitation of file parsing vulnerabilities
  • Stops Information Disclosure: Prevents unauthorized memory access through malicious formulas
  • Eliminates Memory Corruption: Fixes chart rendering vulnerabilities
  • Strengthens Data Connections: Enhanced validation for external data sources
Recommendation: Install this update immediately to protect against active exploitation of these vulnerabilities.

Compatibility and Testing

Microsoft has tested KB5002718 for compatibility with common Excel usage scenarios, including:

  • Standard spreadsheet operations and formulas
  • Chart creation and editing
  • External data connections and queries
  • Macro-enabled workbooks
  • Add-in compatibility
  • Integration with other Office applications

No significant compatibility issues have been identified during testing. However, organizations should test the update in their specific environment before widespread deployment.

Frequently Asked Questions

What does KB5002718 resolve?
KB5002718 resolves four critical security vulnerabilities in Microsoft Excel 2016, including remote code execution (CVE-2026-0847), information disclosure (CVE-2026-0848), memory corruption in chart handling (CVE-2026-0849), and security weaknesses in external data connections. These vulnerabilities could allow attackers to execute arbitrary code or access sensitive information through malicious Excel files.
Which systems require KB5002718?
KB5002718 is required for all systems running Microsoft Excel 2016, including both 32-bit and 64-bit editions across Standard and Professional Plus versions. The update applies to Excel 2016 installations on Windows 10, Windows 11, and Windows Server 2016/2019/2022 operating systems.
Is KB5002718 a security update?
Yes, KB5002718 is a critical security update that addresses multiple high-severity vulnerabilities in Microsoft Excel 2016. It patches remote code execution, information disclosure, and memory corruption vulnerabilities that could be exploited through specially crafted Excel files. Microsoft classifies this as an Important security update.
What are the prerequisites for KB5002718?
Prerequisites include Microsoft Excel 2016 (any edition), minimum 500 MB free disk space, administrative privileges for installation, and closing all Office applications before installation. The update requires Windows 10, Windows 11, or Windows Server 2016/2019/2022 as the base operating system.
Are there known issues with KB5002718?
Known issues include potential installation failures if Office applications are running (error 0x80070643), insufficient disk space errors (0x80240017), slightly slower Excel startup times due to enhanced security checks, and additional security prompts for external data connections. These are generally minor and have available workarounds.

References (3)

About the Author

Emanuel DE ALMEIDA

Emanuel DE ALMEIDA

Senior IT Journalist & Cloud Architect

Microsoft MCSA-certified Cloud Architect | Fortinet-focused. I modernize cloud, hybrid & on-prem infrastructure for reliability, security, performance and cost control - sharing field-tested ops & troubleshooting.

Discussion

Share your thoughts and insights

You must be logged in to comment.

Loading comments...