Junglewise Threat Intelligence

CVE-2026-41101: Microsoft Office Word improper access control spoofing vulnerability

CVE-2026-41101 · Severity: high · CVSS 7.1 · Published 2026-05-12

Technologies: Microsoft Word, Microsoft Office Word. Vendors: Microsoft.

Executive brief

A security vulnerability in Microsoft Word could allow an authorized user on a system to spoof content or identities. This flaw stems from improper access controls within the application, which is a primary tool for document creation and business communication. An attacker successfully exploiting this could misrepresent information or gain unauthorized access to sensitive data, potentially leading to internal fraud or data theft.

Technical details

A vulnerability classified as improper access control (CWE-284) exists in Microsoft Office Word. The flaw allows a locally authenticated attacker with low privileges to bypass security restrictions to perform spoofing attacks. According to the CVSS metrics, the attack does not require user interaction and has a high impact on both confidentiality and integrity, though it does not impact system availability. Users are advised to refer to the Microsoft Security Update Guide for specific patch information and version applicability.

Affected products

  • Microsoft Office Word

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References

Related threats