Executive brief
A security vulnerability in the Microsoft Office installation and update service could allow a user with limited access to gain full administrative control over a computer. This component is responsible for managing how Office applications are installed and kept up to date on Windows systems. If exploited, an attacker who already has a basic account on the machine could bypass security restrictions to access sensitive data or install malicious software.
Technical details
A local privilege escalation vulnerability exists in the Microsoft Office Click-to-Run (C2R) service due to improper access control (CWE-284). An attacker with low-privileged local access can exploit this flaw to execute code with higher privileges, potentially reaching SYSTEM level. The vulnerability is characterized by a CVSS 3.1 score of 8.8, notably featuring a Scope change (S:C), indicating the impact extends beyond the immediate security scope of the Office component. No user interaction is required for exploitation. Microsoft has released security updates to address this issue via the MSRC.
Affected products
- Microsoft Office Click-to-Run (C2R)
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory