Junglewise Threat Intelligence

CVE-2026-35436: Microsoft Office Click-to-Run privilege escalation

CVE-2026-35436 · Severity: high · CVSS 8.8 · Published 2026-05-12

Technologies: Microsoft Office Click-to-Run. Vendors: Microsoft.

Executive brief

A security vulnerability in the Microsoft Office installation and update service could allow a user with limited access to gain full administrative control over a computer. This component is responsible for managing how Office applications are installed and kept up to date on Windows systems. If exploited, an attacker who already has a foothold on a machine could bypass security restrictions to access sensitive data or disrupt operations.

Technical details

A local privilege escalation vulnerability exists in Microsoft Office Click-to-Run due to insufficient granularity of access control (CWE-1220). An attacker with low-privileged local access can exploit this flaw to gain elevated system permissions. The vulnerability is characterized by a 'Changed Scope' (S:C) in the CVSS vector, indicating that the impact extends beyond the security scope of the Click-to-Run component itself. Successful exploitation allows for complete compromise of confidentiality, integrity, and availability on the affected host. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Office Click-to-Run

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References

Related threats