Executive brief
Microsoft Office contains a vulnerability where credentials are not adequately protected, allowing an attacker to impersonate legitimate users or systems over a network. This could enable account takeover, unauthorized access to sensitive documents, or phishing campaigns that appear to come from trusted senders.
Technical details
A credential storage or transmission vulnerability in Microsoft Office allows insufficiently protected credentials to be accessed or manipulated by network-based attackers. The vulnerability enables spoofing attacks without requiring prior authentication or user interaction. While details are limited from the advisory sources, the attack vector is network-based and allows an attacker to impersonate legitimate Office users or sessions. Patches are expected to be available through Microsoft's standard security update channels.
Affected products
- Microsoft Office
Timeline
- 2026-09-08: disclosed