Executive brief
A security vulnerability in the Microsoft Office installation and update service could allow a user with limited access to gain full administrative control over a computer. This component is responsible for managing how Office applications are installed and kept up to date on Windows systems. If exploited, an attacker who already has a foothold on a machine could bypass security restrictions to access sensitive data or disrupt operations.
Technical details
A local privilege escalation vulnerability exists in Microsoft Office Click-to-Run due to insufficient granularity of access control (CWE-1220). An attacker with low-privileged local access can exploit this flaw to gain elevated system permissions. The vulnerability is characterized by a 'Changed Scope' (S:C) in the CVSS vector, indicating that the impact extends beyond the security scope of the Click-to-Run component itself. Successful exploitation allows for complete compromise of confidentiality, integrity, and availability on the affected host. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Office Click-to-Run
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory