Executive brief
A security vulnerability has been identified in Microsoft Office, the widely used suite of productivity applications. This flaw allows an unauthorized person with local access to a computer to impersonate legitimate users or services. Such an exploit could lead to unauthorized data access or the manipulation of sensitive business documents, potentially damaging an organization's data integrity and reputation.
Technical details
A vulnerability classified as improper access control (CWE-284) exists within Microsoft Office. The flaw allows an unauthenticated attacker with local access to the target system to perform spoofing attacks. According to the CVSS vector, the attack requires low complexity and no user interaction, potentially resulting in high impacts on confidentiality and integrity. While specific technical details regarding the affected Office component are not disclosed, the vulnerability is addressed via Microsoft's standard security update process. An attacker could leverage this to misrepresent their identity or the origin of data within the Office environment.
Affected products
- Microsoft Office
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory: Microsoft released the security update guide for this vulnerability.