Junglewise Threat Intelligence

CVE-2026-55035: Microsoft Office out-of-bounds read information disclosure

CVE-2026-55035 · Severity: medium · CVSS 5.5 · Published 2026-07-14

Technologies: Microsoft SharePoint Enterprise Server 2016, Microsoft Office LTSC 2024, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office 2016, Microsoft 365 Apps for Enterprise, Microsoft Office 2019. Vendors: Microsoft.

Executive brief

A security vulnerability in Microsoft Office could allow an attacker to access sensitive information on a user's computer. To exploit this, an attacker would typically need to trick a user into opening a specially crafted file. This could lead to the unauthorized disclosure of private data stored in the system's memory.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in multiple versions of Microsoft Office and SharePoint Server. The flaw is triggered when the application improperly handles memory while parsing a specially crafted file. An attacker can exploit this by convincing a user to open a malicious document, allowing the attacker to read sensitive information from the process memory. This is a local attack vector requiring user interaction, with a CVSS base score of 5.5. Microsoft has released security updates to address this issue across affected products including Office 2016, 2019, LTSC, and Microsoft 365 Apps.

Affected products

  • Microsoft Office 2016 < 16.0.5561.1000
  • Microsoft Office 2019 All versions
  • Microsoft Office LTSC 2021 All versions
  • Microsoft Office LTSC 2024 All versions
  • Microsoft 365 Apps for Enterprise All versions
  • Microsoft Office 365 for Mac < 16.111.26071215
  • Microsoft SharePoint Enterprise Server 2016 < 16.0.5561.1001

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats