CVE-2026-55124
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Exploitability: 1.8 / Impact: 3.6
Source: secure@microsoft.com (Secondary)
Description
Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Affected (17)
Products: Microsoft: 365 Apps, Microsoft 365, Office 2019, Office 2021, Office 2024, Office Online Server, Sharepoint Server, Word
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| Before 16.0.10417.20175 | |
| Before 16.0.19725.20434 | |
| Version 2016 |
Related CWEs
CWE-1287
Improper Validation of Specified Type of Input
The product receives input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.
CWE-20
Improper Input Validation
The product receives input or data, but it does
not validate or incorrectly validates that the input has the
properties that are required to process the data safely and
correctly.
References (1)
Source: secure@microsoft.com
Vendor AdvisoryPatch
Timeline
No history available yet.