7.8
CVE-2026-20956
- EPSS 0.41%
- Veröffentlicht 13.01.2026 17:56:48
- Zuletzt bearbeitet 14.01.2026 19:48:42
- Erkennungen
Microsoft Excel Remote Code Execution Vulnerability
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Office Long Term Servicing Channel Version 2021 SwPlatform - HwPlatform x64
Microsoft ≫ Office Long Term Servicing Channel Version 2021 SwPlatform - HwPlatform x86
Microsoft ≫ Office Long Term Servicing Channel Version 2021 SwPlatform macos
Microsoft ≫ Office Long Term Servicing Channel Version 2024 SwPlatform - HwPlatform x64
Microsoft ≫ Office Long Term Servicing Channel Version 2024 SwPlatform - HwPlatform x86
Microsoft ≫ Office Long Term Servicing Channel Version 2024 SwPlatform macos
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.41% | 0.343 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Microsoft | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-822 Untrusted Pointer Dereference
The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20956