Junglewise Threat Intelligence

CVE-2026-56192: Microsoft Office Out-of-bounds Read Information Disclosure

CVE-2026-56192 · Severity: medium · CVSS 5.5 · Published 2026-07-14

Executive brief

A vulnerability in Microsoft Office could allow an attacker to access sensitive information on a user's computer. This issue affects common productivity tools like Word, Excel, and PowerPoint, as well as SharePoint servers. To exploit this, an attacker would typically need to trick a user into opening a specially crafted file, potentially leading to the exposure of private data.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in multiple versions of Microsoft Office and SharePoint Server. The flaw is triggered when the application fails to properly validate input while reading from a memory buffer, which can be exploited by an attacker who convinces a user to open a malicious file. While the attack vector is local, it requires no prior privileges (PR:N) but does require user interaction (UI:R). Successful exploitation allows the attacker to read sensitive information from the process memory, potentially bypassing security boundaries. Microsoft has released security updates to address this issue across affected platforms including Windows and macOS.

Affected products

  • Microsoft Microsoft 365 Apps for Enterprise 16.0.1 and later versions prior to security updates
  • Microsoft Microsoft Office 2016 16.0.0 to 16.0.5561.1000
  • Microsoft Microsoft Office 2019 19.0.0 and later versions prior to security updates
  • Microsoft Microsoft Office 365 for Mac 1.0.0 to 16.111.26071215
  • Microsoft Microsoft Office LTSC 2021 16.0.1 and later versions prior to security updates
  • Microsoft Microsoft Office LTSC 2024 16.0.0 and later versions prior to security updates
  • Microsoft Microsoft SharePoint Enterprise Server 2016 16.0.0 to 16.0.5561.1001

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats