Junglewise Threat Intelligence

CVE-2026-68792: Microsoft Office command injection in privilege escalation

CVE-2026-68792 · Severity: high · CVSS 7.8 · Published 2026-08-11

Technologies: Microsoft Office. Vendors: Microsoft.

Executive brief

Microsoft Office is a widely-used suite of productivity applications used by organizations for document creation and collaboration. A command injection vulnerability allows an authenticated attacker to execute arbitrary commands with elevated privileges on an affected system, potentially compromising sensitive data or enabling further lateral movement within the network.

Technical details

This vulnerability is a command injection flaw (CWE-78) in Microsoft Office that arises from improper neutralization of special elements in command strings. An authorized attacker can craft malicious input that breaks out of the intended command context and execute arbitrary system commands with elevated privileges. The attack requires authentication and local access to execute; it does not provide remote code execution. Patches are available from Microsoft through their security update guide.

Affected products

  • Microsoft Office <UNKNOWN>

Timeline

  • 2026-08-11: disclosed

References

Related threats