Junglewise Threat Intelligence

CVE-2026-45456: Microsoft Office type confusion local code execution

CVE-2026-45456 · Severity: high · CVSS 8.4 · Published 2026-06-09

Technologies: Microsoft Office. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in Microsoft Office, the widely used suite of productivity applications. This flaw allows an attacker who has gained access to a user's computer to execute malicious code with the same permissions as the logged-in user. If exploited, this could lead to the theft of sensitive documents, unauthorized changes to files, or a complete takeover of the affected workstation.

Technical details

A type confusion vulnerability (CWE-843) exists in Microsoft Office due to the application accessing resources using an incompatible type. The vulnerability is triggered locally and does not require administrative privileges or user interaction to exploit once an attacker has local access. Successful exploitation allows for arbitrary code execution in the context of the current user, potentially leading to full system compromise. Microsoft has released information regarding this vulnerability via their Security Update Guide, and users are advised to apply the latest security patches for Office.

Affected products

  • Microsoft Office

Timeline

  • 2026-06-09: disclosed: Initial disclosure by Microsoft and NVD publication.
  • 2026-06-09: advisory: Microsoft released the security update guide for this vulnerability.

References

Related threats