← Back

CVE-2026-68792

nvd nist
Published: Aug 11, 2026Modified: Aug 14, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: secure@microsoft.com (Secondary)

Description

Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an authorized attacker to elevate privileges locally.

Affected (8)

4 products
365 Apps
Office 2019
Office 2021
Office 2024
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
All versions
All versions
Microsoft
All versions
All versions
Microsoft
All versions
All versions
Microsoft
All versions
All versions

References (1)

Timeline

No history available yet.