7.8

CVE-2026-21509

Warnung
Medienbericht
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft365 Apps Version- SwEditionenterprise HwPlatformx64
Microsoft365 Apps Version- SwEditionenterprise HwPlatformx86
MicrosoftOffice Version2016 HwPlatformx64
MicrosoftOffice Version2016 HwPlatformx86
MicrosoftOffice Version2019 HwPlatformx64
MicrosoftOffice Version2019 HwPlatformx86
MicrosoftOffice Long Term Servicing Channel Version2021 SwPlatform- HwPlatformx64
MicrosoftOffice Long Term Servicing Channel Version2021 SwPlatform- HwPlatformx86
MicrosoftOffice Long Term Servicing Channel Version2024 SwPlatform- HwPlatformx64
MicrosoftOffice Long Term Servicing Channel Version2024 SwPlatform- HwPlatformx86

26.01.2026: CISA Known Exploited Vulnerabilities (KEV) Catalog

Microsoft Office Security Feature Bypass Vulnerability

Schwachstelle

Microsoft Office contains a security feature bypass vulnerability in which reliance on untrusted inputs in a security decision in Microsoft Office could allow an unauthorized attacker to bypass a security feature locally.

Beschreibung

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.91% 0.861
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
secure@microsoft.com 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-807 Reliance on Untrusted Inputs in a Security Decision

The product uses a protection mechanism that relies on the existence or values of an input, but the input can be modified by an untrusted actor in a way that bypasses the protection mechanism.