Junglewise Threat Intelligence

CVE-2026-64904: Microsoft Office type confusion remote code execution

CVE-2026-64904 · Severity: high · CVSS 7.8 · Published 2026-08-11

Technologies: Microsoft Office. Vendors: Microsoft.

Executive brief

Microsoft Office is widely used for creating and editing documents across organizations. A type confusion vulnerability in Office could allow an attacker with local access to execute malicious code with the same privileges as the affected user, potentially leading to data theft, credential compromise, or lateral movement within corporate networks.

Technical details

This vulnerability is a type confusion flaw in Microsoft Office that allows local code execution. The attack requires local access to the affected system, and exploiting it enables an attacker to execute arbitrary code in the context of the Office application. Type confusion vulnerabilities occur when a program accesses a resource using an incompatible type, potentially allowing memory corruption or control flow hijacking. A patch is likely available through Microsoft's standard security update process, though specific remediation details are not yet accessible from the referenced sources.

Affected products

  • Microsoft Office

Timeline

  • 2026-08-11: disclosed

References

Related threats