Executive brief
Microsoft Office is a widely-used suite of productivity applications used by organizations for document creation and collaboration. A command injection vulnerability allows an authenticated attacker to execute arbitrary commands with elevated privileges on an affected system, potentially compromising sensitive data or enabling further lateral movement within the network.
Technical details
This vulnerability is a command injection flaw (CWE-78) in Microsoft Office that arises from improper neutralization of special elements in command strings. An authorized attacker can craft malicious input that breaks out of the intended command context and execute arbitrary system commands with elevated privileges. The attack requires authentication and local access to execute; it does not provide remote code execution. Patches are available from Microsoft through their security update guide.
Affected products
- Microsoft Office <UNKNOWN>
Timeline
- 2026-08-11: disclosed