• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
Hackers

Microsoft Excel Vulnerability Could Put 120 Million Users At Risk

By
Chris Morris
Chris Morris
Former Contributing Writer
Down Arrow Button Icon
By
Chris Morris
Chris Morris
Former Contributing Writer
Down Arrow Button Icon
June 27, 2019, 1:39 PM ET

Researchers have discovered a vulnerability in Microsoft Excel, one of the most widely used productivity programs in the corporate world, that could let attackers take over a user’s system and remotely launch malware.

The flaw, found by the team at Mimecast, lies in the Power Query tool, which lets users integrate spreadsheets with external databases, text documents and Web pages. If exploited by attackers, it can also launch sophisticated, hard-to-detect attacks.

“Using Power Query, attackers could embed malicious content in a separate data source, and then load the content into the spreadsheet when it is opened,” the company said. The malicious code could be used to drop and execute malware that can compromise the user’s machine.”

Microsoft has not issued a fix for the vulnerability at this time, but did release an advisory document for users, offering a workaround to beef up security.

The vulnerability is based upon a method called Dynamic Data Exchange (DDE). Attacks using this method are common, but this one is notable because it gives intruders administrative privileges.

“Because Power Query is a powerful tool within Microsoft Excel, the potential threat for abusing the feature is great,” said Mimecast. “Using the potential weakness in Power Query, attackers could potentially embed any malicious payload that as designed won’t be saved inside the document itself but downloaded from the web when the document is opened.”

More must-read stories from Fortune:

—The fall and rise of VR: The struggle to make virtual reality get real

—“It’s just lazy”: Current’s CEO on Facebook Calibra’s similar logo

—Slack went public without an IPO. Here’s how a direct offering works

—Welcome to the next generation of corporate phishing scams

—Listen to our new audio briefing, Fortune 500 Daily

Catch up with Data Sheet, Fortune‘s daily digest on the business of tech.

About the Author
By Chris MorrisFormer Contributing Writer

Chris Morris is a former contributing writer at Fortune, covering everything from general business news to the video game and theme park industries.

See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

AIOpenAI
OpenAI plans to almost double its headcount this year, FT says
By Liza Tetley and BloombergMarch 21, 2026
1 hour ago
Politicsarms, weapons, and defense
The U.S. has the world’s most advanced military, but the unforgiving economics of wars in Iran and Ukraine show quantity has a quality all its own 
By Jason MaMarch 21, 2026
2 hours ago
AIAI agents
OpenAI cofounder says he hasn’t written a line of code in months and is in a ‘state of psychosis’ trying to figure out what’s possible
By Jason MaMarch 21, 2026
6 hours ago
david
CommentaryScience
The one skill that separates people who get smarter with AI from everyone else
By David Rock and Chris WellerMarch 21, 2026
12 hours ago
Geoffrey Hinton standing in front of a white and grey background.
AITech
‘Godfather of AI’ says tech companies aren’t concerned with the AI endgame. They’re focused on short-term profits instead
By Sasha RogelbergMarch 21, 2026
13 hours ago
MagazineCoding
Cursor’s crossroads: The rapid rise, and very uncertain future, of a $30 billion AI startup
By Allie GarfinkleMarch 21, 2026
13 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.