Junglewise Threat Intelligence

CVE-2026-45460: Microsoft Office out-of-bounds read information disclosure

CVE-2026-45460 · Severity: medium · CVSS 4.7 · Published 2026-06-09

Technologies: Microsoft Office. Vendors: Microsoft.

Executive brief

Microsoft Office is a widely used suite of productivity applications including Word, Excel, and PowerPoint. A security flaw has been identified that could allow an attacker to access sensitive information stored in the computer's memory that should otherwise be protected. To exploit this, an attacker would typically need to trick a user into opening a specially crafted file, potentially leading to the exposure of confidential data.

Technical details

An out-of-bounds read (CWE-126) exists in Microsoft Office. The vulnerability is triggered when the application reads data past the end of the intended buffer, which can lead to the disclosure of sensitive information from the process memory. The attack vector is local, requiring high complexity and user interaction; specifically, an attacker must convince a user to open a malicious file. While the attacker does not need prior privileges, the exploit is limited to information disclosure and does not inherently allow for code execution or data modification. Microsoft has released information regarding this vulnerability via their Security Update Guide.

Affected products

  • Microsoft Office

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats