5.5
CVE-2026-35440
- EPSS 0.45%
- Veröffentlicht 12.05.2026 16:58:36
- Zuletzt bearbeitet 19.05.2026 18:05:26
- Erkennungen
Microsoft Word Information Disclosure Vulnerability
Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Office Long Term Servicing Channel Version 2021 SwPlatform - HwPlatform x64
Microsoft ≫ Office Long Term Servicing Channel Version 2021 SwPlatform - HwPlatform x86
Microsoft ≫ Office Long Term Servicing Channel Version 2024 SwPlatform - HwPlatform x64
Microsoft ≫ Office Long Term Servicing Channel Version 2024 SwPlatform - HwPlatform x86
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.45% | 0.356 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Microsoft | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
|
CWE-552 Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35440