8.4
CVE-2026-40363
- EPSS 0.04%
- Veröffentlicht 12.05.2026 16:58:37
- Zuletzt bearbeitet 13.05.2026 15:34:52
- Quelle secure@microsoft.com
- CVE-Watchlists
- Unerledigt
Microsoft Office Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerMicrosoft
≫
Produkt
Microsoft 365 Apps for Enterprise
Version
16.0.1
Version <
https://aka.ms/OfficeSecurityReleases
Status
affected
HerstellerMicrosoft
≫
Produkt
Microsoft Office 2016
Version
16.0.0
Version <
16.0.5552.1000
Status
affected
HerstellerMicrosoft
≫
Produkt
Microsoft Office 2019
Version
19.0.0
Version <
https://aka.ms/OfficeSecurityReleases
Status
affected
HerstellerMicrosoft
≫
Produkt
Microsoft Office for Android
Version
16.0.1
Version <
16.0.19822.20190
Status
affected
HerstellerMicrosoft
≫
Produkt
Microsoft Office LTSC 2021
Version
16.0.1
Version <
https://aka.ms/OfficeSecurityReleases
Status
affected
HerstellerMicrosoft
≫
Produkt
Microsoft Office LTSC 2024
Version
16.0.0
Version <
https://aka.ms/OfficeSecurityReleases
Status
affected
HerstellerMicrosoft
≫
Produkt
Microsoft Office LTSC for Mac 2021
Version
16.0.1
Version <
16.109.26051019
Status
affected
HerstellerMicrosoft
≫
Produkt
Microsoft Office LTSC for Mac 2024
Version
16.0.0
Version <
16.109.26051019
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.04% | 0.136 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| secure@microsoft.com | 8.4 | 2.5 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-122 Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().