Junglewise Threat Intelligence

CVE-2026-55027: Microsoft Office out-of-bounds read information disclosure

CVE-2026-55027 · Severity: medium · CVSS 5.5 · Published 2026-07-14

Technologies: Microsoft SharePoint Enterprise Server 2016, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2024, Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021, Microsoft Office 2016, Microsoft 365 Apps for Enterprise, Microsoft SharePoint Server 2019, Microsoft Office 2019. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in Microsoft Office and SharePoint products that could allow an attacker to access sensitive information. To exploit this, an attacker would typically need to convince a user to open a specially crafted file on their computer. While this does not allow for direct control of the system, it could lead to the unauthorized disclosure of private data stored in the computer's memory.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in multiple versions of Microsoft Office and SharePoint Server. The flaw is triggered when the application fails to properly validate input, allowing a local attacker to read data beyond the intended buffer. Exploitation requires user interaction, such as opening a malicious file. Successful exploitation results in information disclosure, potentially exposing sensitive memory contents to the attacker. Microsoft has addressed this through security updates across the affected product lines.

Affected products

  • Microsoft Microsoft 365 Apps for Enterprise 16.0.1 to latest security release
  • Microsoft Microsoft Office 2016 16.0.0 to 16.0.5561.1000
  • Microsoft Microsoft Office 2019 19.0.0 to latest security release
  • Microsoft Microsoft Office 365 for Mac 1.0.0 to 16.111.26071215
  • Microsoft Microsoft Office LTSC 2021 16.0.1 to latest security release
  • Microsoft Microsoft Office LTSC 2024 16.0.0 to latest security release
  • Microsoft Microsoft Office LTSC for Mac 2021 16.0.1 to 16.111.26071215
  • Microsoft Microsoft Office LTSC for Mac 2024 16.0.0 to 16.111.26071215
  • Microsoft Microsoft SharePoint Enterprise Server 2016 16.0.0 to 16.0.5561.1001
  • Microsoft Microsoft SharePoint Server 2019 16.0.0 to latest security release

Timeline

  • 2026-07-14: advisory: Initial publication by Microsoft and NVD
  • 2026-07-14: patched: Security updates released by Microsoft

References

Related threats