Junglewise Threat Intelligence

CVE-2026-45458: Microsoft Office type confusion local code execution

CVE-2026-45458 · Severity: high · CVSS 8.4 · Published 2026-06-09

Technologies: Microsoft Office. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in Microsoft Office, the widely used suite of productivity applications. This flaw could allow an attacker who has gained access to a user's computer to execute malicious code with the same permissions as the logged-in user. Such an exploit could lead to the theft of sensitive documents, unauthorized data modification, or a complete compromise of the affected workstation.

Technical details

Microsoft Office is vulnerable to a type confusion flaw (CWE-843), though Microsoft's advisory also references Use After Free (CWE-416) characteristics. The vulnerability occurs when the application accesses a resource using an incompatible type, leading to memory corruption. An attacker with local access to the system can exploit this to execute arbitrary code in the context of the current user. The attack vector is local, and according to the CVSS metrics, it requires no elevated privileges or user interaction to trigger. Users are advised to apply the latest security updates from Microsoft to mitigate this risk.

Affected products

  • Microsoft Office

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats