Junglewise Threat Intelligence

CVE-2026-55050: Microsoft Office Word out-of-bounds read information disclosure

CVE-2026-55050 · Severity: medium · CVSS 5.5 · Published 2026-07-14

Technologies: Microsoft SharePoint Enterprise Server 2016, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2024, Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021, Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019, Microsoft 365 Apps for Enterprise, Microsoft Office 2019. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in Microsoft Office Word and related SharePoint services that could allow an attacker to access sensitive information. To exploit this, an attacker would need to convince a user to open a specially crafted file on their computer. While this does not allow for direct control of the system, it could lead to the unauthorized disclosure of private data.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in Microsoft Office Word and SharePoint Server components. The flaw is triggered when the application processes a specially crafted file, leading to memory disclosure. The attack vector is local, requiring user interaction (UI:R) to open a malicious document. Successful exploitation allows an unauthenticated attacker to read sensitive information from the process memory, though it does not provide a mechanism for code execution or data modification. Microsoft has released security updates to address this issue across affected Office and SharePoint versions.

Affected products

  • Microsoft Microsoft 365 Apps for Enterprise 16.0.1 and later versions prior to security updates
  • Microsoft Microsoft Office 2019 19.0.0 and later versions prior to security updates
  • Microsoft Microsoft Office 365 for Mac 1.0.0 to 16.111.26071215
  • Microsoft Microsoft Office LTSC 2021 16.0.1 and later versions prior to security updates
  • Microsoft Microsoft Office LTSC 2024 16.0.0 and later versions prior to security updates
  • Microsoft Microsoft Office LTSC for Mac 2021 16.0.1 to 16.111.26071215
  • Microsoft Microsoft Office LTSC for Mac 2024 16.0.0 to 16.111.26071215
  • Microsoft Microsoft SharePoint Enterprise Server 2016 16.0.0 to 16.0.5561.1001
  • Microsoft Microsoft SharePoint Server 2019 16.0.0 to 16.0.10417.20175
  • Microsoft Microsoft SharePoint Server Subscription Edition 16.0.0 and later versions prior to security updates

Timeline

  • 2026-07-14: disclosed: Initial publication by Microsoft and NVD
  • 2026-07-14: patched: Security updates made available via Microsoft Update Guide

References

Related threats