Junglewise Threat Intelligence

CVE-2026-55142: Microsoft Office Word numeric truncation information disclosure

CVE-2026-55142 · Severity: medium · CVSS 5.5 · Published 2026-07-14

Executive brief

A security vulnerability exists in Microsoft Word and related Office products that could allow an attacker to access sensitive information. To exploit this, an attacker would typically need to trick a user into opening a specially crafted file on their computer. While this does not allow for full system takeover, it could lead to the unauthorized disclosure of private data stored on the local machine.

Technical details

A numeric truncation error (CWE-197) exists in Microsoft Office Word and SharePoint Server components. The vulnerability is triggered when the application incorrectly handles specific numeric values, potentially leading to an information disclosure. An attacker must rely on user interaction, such as convincing a target to open a malicious document, to execute the exploit locally. Successful exploitation allows the attacker to read sensitive information from the memory or local environment of the affected application. Microsoft has released security updates to address this issue across various versions of Office and SharePoint.

Affected products

  • Microsoft Office Word 2016 16.0.1 to 16.0.5561.1000
  • Microsoft Office 2019 19.0.0 and later affected versions
  • Microsoft Office LTSC 2021 16.0.1 and later affected versions
  • Microsoft Office LTSC 2024 16.0.0 and later affected versions
  • Microsoft 365 Apps for Enterprise 16.0.1 and later affected versions
  • Microsoft Office 365 for Mac 1.0.0 to 16.111.26071215
  • Microsoft SharePoint Enterprise Server 2016 16.0.0 to 16.0.5561.1001
  • Microsoft SharePoint Server 2019 16.0.0 to 16.0.10417.20175
  • Microsoft SharePoint Server Subscription Edition 16.0.0 to 16.0.19725.20434

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats