Forum Discussion
Excel x64/VBE event entry loses execute permission in the default segment heap
Excel x64/VBE event entry loses execute permission in the default segment heap; reproduced after Office update
Please route to the Office VBA runtime team and Windows heap team. We need a supported runtime fix or deployment workaround, not DEP/ASLR disablement or VBA page-permission patching.
Environment: Windows 11 Pro 25H2 build 26200.9457; ntdll 10.0.26100.9278. Excel x64 16.0.20430.20140 updated through official Click-to-Run to 16.0.20430.20146. VBE7.DLL remains 7.1.11.58, unchanged SHA256; Microsoft signatures Valid. Retail Office 2021 + Project 2024. No heap override or disabled mitigations.
A fresh native blank workbook (15 blank sheets, counters/empty document-method bodies) plus ordinary GetProcessHeap/HeapAlloc/HeapFree DATA allocations reproduces the same execute AV seen in our business workbook. No PMS business implementation, save/protection logic, project data, license logic, userform, custom executable buffers or permission-writing APIs are present in the minimal fixture.
After the update, the SAME isolated repro ran with CDB attached. All generated VBE entries were initially executable. A paired entry/return of the SAME NtAllocateVirtualMemoryEx call recorded base 0x1b8ef147000, size 0x3c000, MEM_COMMIT, PAGE_READWRITE. The live VBE entry page 0x1b8ef166000 changed from protection 0x40 to 0x04. !heap -x confirmed the allocation was still LFH Allocated (requested 4144, block 4352), with entry bytes intact. A normal Worksheets.Add then delivered Workbook_NewSheet and faulted at 0x1b8ef166dc4: C0000005, Parameter[0]=8. Stack includes DispCallFuncAmd64, VBE7 EpiInvokeMethod and EVENT_SINK_Invoke.
The permission-change stack is RtlAllocateHeap -> LFH subsegment reformat -> SegLfhVsCommit -> SegPageRangeCommit -> SegMgrCommit -> NtAllocateVirtualMemoryEx. An earlier minimal run and the original/freshly rebuilt business project also showed this mechanism. Rebuilding VBA compilation state did not remove it. Traditional-heap business/save smoke acceptance passed, but that is not a portable commercial fix.
Limitations: the compact fixture has reproduced with CDB attached; two no-debugger minimal runs were negative. We do not claim universal impact or an already accepted Microsoft bug. Heap documentation warns against executable permission changes on heap allocations, so ownership of the VBE/heap interaction requires vendor assessment.
Reviewed minimal workbooks/source and sanitized paired traces are available in a small technical package. No real project, license credentials, private keys, Microsoft DLLs or full dump will be uploaded.
Please advise: (1) supported VBE allocation/protection behavior; (2) serviced runtime/Windows build fixing this precise mechanism; (3) supported administrator-deployable mitigation pending servicing; (4) private upload/case route for the minimal evidence. The latest Office update was tested and still reproduces.
https://1drv.ms/u/c/1644b30db0d6b1af/IQBeYS8AqSSGQrK18Grn-wSIAfaKRoioKUlgAWOSZILSR9k?e=GztbpL