7
CVE-2026-20943
- EPSS 0.07%
- Veröffentlicht 13.01.2026 17:56:45
- Zuletzt bearbeitet 16.01.2026 16:14:34
- Quelle secure@microsoft.com
- CVE-Watchlists
- Unerledigt
Untrusted search path in Microsoft Office allows an unauthorized attacker to execute code locally.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Office Deployment Tool Version < 16.0.19426.20170
Microsoft ≫ Sharepoint Server SwEditionsubscription Version < 16.0.19127.20442
Microsoft ≫ Sharepoint Server Version2016 SwEditionenterprise
Microsoft ≫ Sharepoint Server Version2019
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.07% | 0.222 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| secure@microsoft.com | 7 | 1 | 5.9 |
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-426 Untrusted Search Path
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.