Executive brief
A vulnerability in Microsoft Office and SharePoint could allow an unauthorized person with local access to a computer to view sensitive information. This issue affects various versions of the productivity suite, including Office 2016, 2019, and Microsoft 365 Apps. While the attacker must have local access to the system, a successful exploit could lead to the unauthorized disclosure of data stored or processed by these applications.
Technical details
An integer overflow vulnerability (CWE-190) exists in Microsoft Office and SharePoint Server. The flaw is triggered when the application incorrectly handles specific numerical calculations, leading to a wraparound condition. An attacker with local access to the affected system can exploit this to bypass memory protections and disclose sensitive information from the process memory. The vulnerability affects multiple platforms including Windows (32-bit and x64) and macOS. Microsoft has released security updates to address this issue across the affected product lines.
Affected products
- Microsoft Microsoft 365 Apps for Enterprise < 16.0.1
- Microsoft Microsoft Office 2016 < 16.0.5561.1000
- Microsoft Microsoft Office 2019 < 19.0.0
- Microsoft Microsoft Office 365 for Mac < 16.111.26071215
- Microsoft Microsoft Office LTSC 2021 < 16.0.1
- Microsoft Microsoft Office LTSC 2024 < 16.0.0
- Microsoft Microsoft Office LTSC for Mac 2021 < 16.111.26071215
- Microsoft Microsoft Office LTSC for Mac 2024 < 16.111.26071215
- Microsoft Microsoft SharePoint Enterprise Server 2016 < 16.0.5561.1001
- Microsoft Microsoft SharePoint Server 2019 < 16.0.0
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory