Executive brief
A vulnerability in Microsoft Office could allow an attacker to run unauthorized code on a target computer. Microsoft Office is a widely used suite of productivity applications including Word, Excel, and PowerPoint. If exploited, this flaw could allow an attacker to gain full control over the affected system, potentially leading to the theft of sensitive data or the installation of malware.
Technical details
A type confusion vulnerability (CWE-843) exists in Microsoft Office across multiple platforms, including Windows, macOS, and Android. The flaw occurs when the application accesses a resource using an incompatible type, which can be leveraged by a local attacker to execute arbitrary code. While the attack vector is local, the Microsoft-provided CVSS score indicates that no special privileges or user interaction are required for successful exploitation. Affected versions include Office 2016, 2019, LTSC 2021/2024, and Microsoft 365 Apps. A patch is available via the Microsoft Security Update Guide.
Affected products
- Microsoft Office 2016
- Microsoft Office 2019
- Microsoft Office LTSC 2021
- Microsoft Office LTSC 2024
- Microsoft 365 Apps for Enterprise
- Microsoft Office for Android before 16.0.19822.20000
Timeline
- 2026-03-10: disclosed
- 2026-03-10: advisory: Microsoft published the security update guide.