Junglewise Threat Intelligence

CVE-2026-55124: Microsoft Office Word information disclosure via improper input validation

CVE-2026-55124 · Severity: medium · CVSS 5.5 · Published 2026-07-14

Executive brief

A vulnerability in Microsoft Office Word could allow an attacker to gain unauthorized access to sensitive information on a user's computer. To exploit this, an attacker would typically need to trick a user into opening a specially crafted file. This could lead to the exposure of private data, though it does not allow the attacker to modify files or take full control of the system directly.

Technical details

An information disclosure vulnerability exists in Microsoft Office Word due to improper validation of specified input types (CWE-1287). The vulnerability is triggered when the application fails to correctly handle malformed data within a document. An attacker can exploit this by convincing a local user to open a malicious file, leading to the unauthorized disclosure of sensitive memory contents or local files. The attack requires user interaction (UI:R) and is executed with local vector (AV:L) privileges. Microsoft has released security updates to address this issue across affected versions of Office and SharePoint.

Affected products

  • Microsoft Office Word Microsoft 365 Apps, Office 2019, Office LTSC 2021/2024, SharePoint Server

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats